Usable with caveats: the package is clearly licensed, tested, documented, and not deprecated or archived. However, it has only two releases, no security policy or scanning, and repository activity appears limited since December 2025.
72%
Total Score
50
50
83
80
Thirteen runtime dependencies, including several Symfony and project-specific packages, create a moderately broad dependency surface and increase upgrade coordination compared with a small standalone library.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, providing limited institutional backing.
Only two releases have been published, with the latest about 10 months before collection; the 13-day median interval shows an initial release burst but limited long-term maintenance evidence.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not establish that a small package is unsafe to use.
Composer build tooling is present, but no security-scanning tool was detected, leaving a transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
symfony/yaml Version ^7.3 | — | — |
symfony/config Version ^7.3 | — | — |
monolog/monolog Version ^3.1 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.