The license, README, matching repository, and organization ownership provide clear packaging context. Its narrow metapackage design explains the lack of tests and workflows, but does not establish long-term upkeep.
68%
Total Score
75
100
83
83
This is the package's first and only release, published today, so there is no release cadence or track record yet. That limits confidence in ongoing maintenance rather than showing abandonment.
The repository has no commits or active maintainers in the last three months, with only the initial publication visible. Its same-day creation partly explains this, but provides no evidence of sustained upkeep.
Composer is used for the build, but no security-scanning tool is configured. This is a modest hygiene gap for a narrow package, not evidence of unsafe code.
The linked repository has no security policy. For a small generated type-definition metapackage this is a transparency gap, though the package has no install-time scripts or workflow activity that would amplify it.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/symfony-dependency-injection-impl Version ~7.4.17.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.