The package is clearly licensed and intentionally minimal for a Composer type-definition metapackage. Organization backing, package-name alignment, and a clean dependency setup support adoption, but there is not yet enough history to demonstrate sustained maintenance.
72%
Total Score
75
100
86
75
The package was released only once, on the assessment date, and has no established release cadence. Its zero-day age makes this an unproven project rather than evidence of abandonment.
No commits or active maintainers were recorded in the preceding three months, but the repository and package are only zero days old; this is limited evidence, not a collapse in activity.
Composer build tooling is present, fitting the ecosystem and package format. No security-scanning tool was detected, which is a minor hygiene gap for a newly published package.
The repository has no security policy. This is a modest transparency gap, though the package is a minimal type-definition metapackage with no reported security workflow or install-time script.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/symfony-psr-http-message-bridge-impl Version ~7.4.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.