Organization backing, a matching repository, tests, and Apache-2.0 licensing add useful transparency. The package is still too new to establish dependable long-term maintenance, so pinning this exact version is prudent.
68%
Total Score
75
100
88
83
This is the first and only release, published 0 days ago, so there is no release track record to demonstrate sustained maintenance. Its freshness explains the gap but does not remove the uncertainty.
No commits or active maintainers were observed in the prior 3 months. Because the repository was created only 0 days ago, this indicates unproven maturity rather than established abandonment.
Composer is used as a build tool, supporting the package's ecosystem conventions, although no security scanning tool was detected. The missing scanner is a secondary hygiene gap, not a severe concern alone.
The repository has no security policy. For a newly created small package this limits vulnerability-reporting transparency, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache-contracts Version 3.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.