The package includes tests, a matching repository, and a clear MIT license. Four workflow actions are unpinned, and no security scanning or policy is present.
60%
Total Score
50
50
79
67
The release declares 31 runtime dependencies, creating a broad dependency surface and more compatibility and maintenance exposure than a small, focused bundle.
The repository is owned by a user account rather than an organization, so there is no observed organizational backing to offset the thin maintenance history.
This is the package's only release, published about 16 months ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain.
There were no commits and no active maintainers in the last three months. Combined with one release overall, this is a meaningful sign of slowing or paused maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
twig/twig Version ^3.13|^4.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^6.4 || ^7.1 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.