Usable with caveats: the package is licensed, documented, tested, and not deprecated or archived, but it has only one 0.0.1 release and no commits from any maintainer in the last three months. Its broad dependency footprint and limited security governance add maintenance risk.
58%
Total Score
50
50
78
80
There were zero commits and zero active maintainers in the last three months. Together with the single-release history, this is meaningful evidence of currently weak maintenance activity.
The package declares 31 runtime dependencies, including substantial Symfony, Doctrine, EasyAdmin, and WeChat infrastructure, creating a comparatively large compatibility and maintenance surface.
The registry namespace and repository owner match, but the owner is an individual rather than an organization. This provides direct ownership alignment without the capacity signal that organizational backing could provide.
Only one release exists, published about 10 months ago, so there is little evidence of release maturity or a sustained maintenance cadence.
The repository has zero stars, forks, and watchers. This is limited supporting evidence rather than a verdict, but it provides no external adoption signal to offset the thin release and maintenance history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.