The package is licensed, tested, and backed by an organization, with no install-time scripts or deprecation. Its very limited project history makes long-term maintenance capacity hard to establish.
62%
Total Score
75
100
83
67
This is the package's first release, published 0 days ago, so there is no release track record to demonstrate sustained maintenance. Its recency explains the gap but does not remove the uncertainty.
The repository shows 0 commits and 0 active maintainers in the last 3 months. Because the package is brand new, this is mainly an absence of maintenance evidence rather than proof of abandonment, but it lowers confidence.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but the complete absence of adoption signals adds to the uncertainty for a first release.
Composer is used as the build tool, but no security-scanning tooling is reported. For a small implementation package this is a hygiene gap rather than a severe dependency risk.
No security policy is present. This is a transparency gap, although the small, newly published package has limited history from which to establish a security process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/event-dispatcher-contracts Version 3.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.