The package is clearly documented, licensed, and intentionally small, with no install-time scripts. Its organization-backed repository matches the package, but there is not yet enough history to establish dependable maintenance.
68%
Total Score
75
100
88
88
This is a brand-new package: it has one release and is 0 days old, so there is no release history to demonstrate continuity or reliability yet.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this is mainly an unproven maintenance record rather than evidence of abandonment, but it limits confidence.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tool is configured. For a small metapackage this is a modest hygiene gap, not a severe risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package is a small metapackage with no install-time scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/symfony-flex-impl Version ~2.11.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.