The package has a clear README, a stable major release, and no install-time scripts. Its license declaration conflicts with the license identified in the artifact, and its source project lacks security tooling.
20%
Total Score
67
75
75
The linked repository is archived, making future fixes and maintenance unlikely even though it was pushed recently. Organization backing does not offset the repository's explicit archived status.
The package declares EUPL-1.1, while the artifact license file was detected as EPL-1.0. Both the artifact and repository contain license files, so this is a license consistency concern rather than an absent-license gap.
All recent commit activity comes from one contributor. The organization-owned project provides some handoff capacity, but no second active contributor is evidenced.
Only 1 commit was recorded in the last 3 months, from 1 active maintainer, which indicates very limited recent maintenance.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a modest maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phlak/semver Version ^3.0.1 | — | — |
symfony/config Version ^7.0 | — | — |
symfony/finder Version ^7.0 | — | — |
symfony/console Version ^7.0 | — | — |
symfony/filesystem Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.