The repository includes tests and the package has a clear MIT license, but its small maintainer base and absent security policy reduce confidence. Workflow review found no dangerous patterns, though both referenced actions are unpinned.
62%
Total Score
50
50
88
50
The package declares 10 runtime dependencies, including several Symfony components; this is substantial for a focused utility and increases dependency maintenance surface.
Only one registry account has publishing access, which creates some continuity risk for a young package; the repository owner is an individual rather than an organization.
The repository is owned by an individual account, so there is no observed organizational backing to offset the single-publisher and small-project risks.
This is a young package released once 106 days ago, so there is limited evidence of release consistency and long-term maintenance.
There were no commits and no active maintainers in the past three months, leaving little evidence of continuing development beyond the initial release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/uid Version ^7.3 || ^8.0 | — | — |
symfony/form Version ^7.3 || ^8.0 | — | — |
symfony/config Version ^7.3 || ^8.0 | — | — |
symfony/http-client Version ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.