This release appears healthy and reasonably safe to depend on: it has a stable non-prerelease version, frequent recent releases, an active non-archived repository, tests and changelog coverage, explicit MIT licensing, and recent activity from two contributors. The main reservations are modest repository popularity, absent security scanning and security policy, and GitHub Actions permission and untrusted-checkout concerns in the release workflow; these warrant review but do not outweigh the strong maintenance and project-structure evidence.
82%
Total Score
100
100
89
70
Both workflows were analyzed with no script injection or pull_request_target findings, but the release workflow contains an untrusted checkout in a workflow_run context, creating a meaningful workflow-hardening concern.
Two stars, zero forks, and one watcher indicate very limited external adoption and independent review. Popularity is supporting evidence rather than a verdict, so this is a caution rather than a severe health failure.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning lowers supply-chain transparency somewhat, though it is not by itself evidence of an unhealthy package.
The repository has no SECURITY.md or equivalent security policy, leaving vulnerability-reporting and response expectations unclear.
The release workflow lacks top-level token permissions, and the CI workflow declares top-level write permissions; these defaults are broader or less explicit than ideal and warrant workflow review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.4.15 || ^8.0 | — | — |
symfony/runtime Version ^7.4.14 || ^8.0 | — | — |
symfony/serializer Version ^7.4.15 || ^8.0 | — | — |
symfony/http-client Version ^7.4.15 || ^8.0 | — | — |
phpstan/phpdoc-parser Version ^2.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.