Documentation, licensing, tests, and organization backing provide useful transparency. Maintenance has paused recently, while workflow references are all unpinned and no repository security scanning is reported.
65%
Total Score
75
50
89
50
The release declares 20 runtime dependencies, including several Symfony and HTTP components. This is a substantial dependency surface and increases the maintenance burden, but it is not inherently unhealthy.
The package runs post-install and post-update Composer scripts. These add installation-time behavior that consumers should inspect, though the signal does not establish that the scripts are unsafe.
The repository recorded no commits and no active maintainers during the latest three months. This is a meaningful maintenance concern, although the recent release history shows activity over the broader period.
The repository has no stars or forks and one watcher. This indicates limited external adoption, but popularity is supporting evidence only and does not outweigh the package's release history and organization backing.
The repository uses Composer for builds, but no security-scanning tool was detected. The missing scanning is a modest transparency and maintenance gap, not evidence of a specific vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.4 | — | — |
lmc/cqrs-http Version ^3.0 | — | — |
lmc/cqrs-types Version ^3.1 | — | — |
symfony/config Version ^6.3 | — | — |
beberlei/assert Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.