The small contract package is well documented, tested, licensed, and has a stable 1.0.0 release. Its repository has had no commits in three months, and all three workflow actions are unpinned. No security policy is published, leaving modest transparency and maintenance concerns.
70%
Total Score
50
100
83
83
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is no clear organizational backing to offset the thin activity evidence.
The package has three releases over 496 days, with one release in the last 12 months and a median interval of about 88 days. This shows an established release history but a currently slow cadence.
There were no commits and no active maintainers in the last three months. For a tiny, stable interface package this may reflect completion, but it weakens evidence of ongoing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little external validation.
Composer build tooling is present, but no security scanning tools are configured. This is a modest repository hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/security-core Version ^7.3 | — | — |
symfony/dependency-injection Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.