The component is narrowly scoped and has a README, tests, and a stable MIT license. Organization ownership and a repository README mentioning the package add some continuity, but no security policy leaves transparency weaker.
63%
Total Score
75
100
88
83
The latest release was over three years ago, with no releases in the last 12 months and a median interval of about 21 months. This indicates slow maintenance, though the package is small and stable.
There were no commits or active maintainers in the last three months. Combined with the old latest release, this is meaningful evidence of slow current maintenance.
The repository uses Composer for builds, which fits the package ecosystem, but it has no security-scanning tools. This is a minor transparency and hygiene gap.
The repository has no security policy. For a small component this is not severe, but it weakens the project's documented process for handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^5.3 | — | — |
wonderwp/dependency-injection Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.