The package includes tests, a clear README, and a source tree that matches its registry identity. Licensing and read-only workflow permissions are also in place, though security scanning and broader recent contributor activity are limited.
82%
Total Score
67
94
67
All 1 recent commit came from a single contributor. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
Only 1 commit was recorded in the last 3 months, so recent development activity is limited despite the package's recent release history.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. This is a minor transparency gap for a maintained package, not evidence that the release is unsafe.
The workflow uses read-only permissions and has no audited findings, with complete coverage. However, its single action reference is unpinned, which is a small reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
doctrine/dbal Version ^3.3 || ^4.0 | — | — |
symfony/config Version ^6 || ^7 | — | — |
contao/core-bundle Version ^5.3 | — | — |
symfony/http-kernel Version ^6 || ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.