It has an MIT license, tests, and a matching repository with release notes. Its 37 runtime dependencies, four unpinned workflow actions, and lack of security tooling add maintenance and transparency concerns.
65%
Total Score
50
50
75
75
Thirty-seven runtime dependencies create substantial upgrade and compatibility overhead for a 0.0.1 package, although the dependencies are explicit rather than hidden.
This is a young package with only one release, published about 10 months ago, so its maintenance and maturity are not yet well established.
There were zero commits and zero active maintainers in the last three months, which is a meaningful warning for a package with only one release.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a decisive concern because popularity is not required for a small maintained package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
nesbot/carbon Version ^2.72 || ^3 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.