Usable with caveats: it is actively maintained, clearly documented, backed by an organization, and has a strong recent release cadence. Adoption still depends heavily on one contributor, and the project lacks a security policy and security scanning.
72%
Total Score
90
100
89
88
All 13 recent commits came from a single contributor, creating a real continuity risk. Organization backing provides some ability to hand maintenance off, but no second active contributor is shown to offset the concentration.
Composer is used for builds, but no security-scanning tool is detected. The missing scanning lowers transparency around dependency and build hygiene, though it is not evidence of malicious behavior.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for consumers.
Version 0.0.30 is not a prerelease, but the 0.x major version indicates an API that may still change substantially and is less mature than a stable 1.x release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.4 | — | — |
wexample/symfony-helpers Version >=8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.