Its README, changelog, MIT license, and small dependency set make the package straightforward to inspect. The release workflow uses two unpinned actions, including one from an archived repository, so its publishing setup needs care.
58%
Total Score
83
100
83
83
The package has had no releases in the last 12 months, and its latest release was nearly two years ago. Fifteen total releases show some prior activity, but the current gap raises maintenance risk.
There were no commits or active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has no stars or forks and only one watcher, offering little independent evidence of adoption. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
Composer build tooling is present, but no security scanning tooling was detected. For this small package, that is a hygiene gap rather than a severe risk.
The repository has no security policy, reducing transparency around vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.