Tours for vivutio: itineraries day by day through the destinations, where each night is spent, and what the parks charge a party.
61%
Total Score
caution
A brand-new package has no demonstrated maintenance history, and its workflows use five unpinned actions.
The package declares 19 runtime dependencies, including framework, ORM, security, and application-package dependencies. This is a substantial dependency surface for a new package and increases integration and update burden.
The package is only 0 days old, with 10 releases clustered within one day and a median interval of about 30 minutes. This shows active initial publishing but not sustained maintenance, so the evidence is limited.
There were 0 commits and 0 active maintainers in the last 3 months, but the package and repository are only 0 days old. This is insufficient history rather than clear abandonment, so it remains a concern about demonstrated continuity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning layer is a modest repository hygiene gap for a package with 19 runtime dependencies.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations, although it is not evidence of an active security issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
twig/twig Version ^3.21 | — | — |
symfony/uid Version ^8.0 | — | — |
doctrine/orm Version ^3.5 | — | — |
symfony/intl Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.