Usable with caveats: the release is clearly packaged, tested, licensed, and backed by a matching repository, but it is brand new with no established maintenance or adoption history. Review future activity before making it a long-term dependency.
68%
Total Score
75
100
89
80
Only one registry account has publishing access. That is not inherently unhealthy for a user-owned project, but it leaves a thin publishing base if the maintainer becomes unavailable.
The package has only three releases and was first published today, with releases arriving within minutes of one another. This shows active initial publishing but provides no longer-term maintenance record.
There were no commits or active maintainers during the last three months, but the repository was created or updated today, so the metric reflects the package's very short history rather than a demonstrated collapse in maintenance.
The repository has zero stars, forks, and watchers. This is understandable for a package published today, but it provides no independent adoption evidence yet.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less significant for a small package with no established user base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.13 | — | — |
doctrine/orm Version ^2.14 || ^3.0 | — | — |
symfony/config Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/console Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.