The Apache-2.0 license, matching repository, and organization backing add useful transparency. Its single release and no observed commit history leave maintenance maturity unproven; pin this exact version.
65%
Total Score
75
100
88
75
This package was released today and has only one release, so there is no meaningful release track record yet. That limits evidence of maintenance maturity, though it is consistent with a newly published package.
The repository has zero commits and zero active maintainers in the last three months. Because the package is newly published, this is limited evidence rather than proof of abandonment, but ongoing maintenance capacity remains unproven.
The repository uses Composer, matching the package ecosystem, but no security-scanning tooling was detected. For this minimal metapackage the missing scanner is a hygiene gap, not a severe dependency risk.
The repository has no security policy. This is a transparency and reporting gap, although the package is a small metapackage with no install-time lifecycle scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/symfony-event-dispatcher-contracts-impl Version ~3.7.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.