A single maintainer and no security policy reduce resilience. The project has tests, release notes, and dependency scanning, which provide useful safeguards.
66%
Total Score
63
100
94
75
Only one account has registry publish access, which limits publishing resilience and creates a single point of failure. The linked repository is user-owned, so there is no organization backing to offset that limitation.
The repository had zero commits and zero active maintainers in the last three months. The recent release and recent repository push partly offset this, but the lack of sustained commit activity raises maintenance risk.
There were no new or closed issues and no merged pull requests in the last month, while 30 issues remain open. This indicates limited recent community activity.
No repository security policy is present, leaving vulnerability reporting and response expectations undocumented.
The release is not a prerelease, but the project remains below major version 1, so compatibility expectations are somewhat less mature than for a stable-major package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 || ^7.0 | — | — |
tomzx/finder Version ^0.2 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
nikic/php-parser Version ^5.2 | — | — |
hassankhan/config Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.