Healthy and actively maintained, with a strong release record and a working source repository. The main caveats are concentrated contribution activity and no documented security policy or scanning setup.
82%
Total Score
83
100
89
75
The package defines post-install and post-update Composer scripts, which add install-time behavior that should be reviewed before adoption. No provided signal shows these scripts are dangerous, so this is a limited concern rather than a severe risk.
One contributor made 42 of 45 recent commits, creating a concentrated maintenance dependency. The second active contributor and organization-owned repository provide some handoff capacity, so this is caution rather than danger.
The repository has no stars, forks, or watchers, so there is little external adoption evidence. This is only supporting evidence and is outweighed by the strong release and commit activity.
Composer build tooling is present, but no security-scanning tool was detected. That weakens automated assurance without showing that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, not evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wexample/php-date Version >=2.0.0 | — | — |
wexample/symfony-forms Version >=6.0.0 | — | — |
wexample/symfony-loader Version >=6.0.0 | — | — |
wexample/symfony-content Version >=2.0.0 | — | — |
wexample/symfony-helpers Version >=8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.