A clear README, tests, MIT licensing, and release notes make integration transparent. Security policy and automated security scanning are absent, so pinning this early release is prudent.
64%
Total Score
50
100
79
83
The registry namespace and repository are owned by the same individual, which supports package identity but provides no organizational maintenance cushion.
The package is 61 days old with only one release, so its maintenance pattern and long-term reliability are not yet established.
All recent commits come from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset that concentration.
One commit from one active maintainer in the last three months confirms recent activity, but the very small amount of activity provides limited evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tool was detected. That weakens supply-chain transparency for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/validator Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-foundation Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.