The package includes tests, release notes, a clear README, and a non-deprecated stable release. No commits were recorded in the last three months, and all three workflow actions are unpinned, leaving maintenance and build-integrity concerns.
68%
Total Score
83
100
83
83
This is a young package with only one release, published about 159 days ago, so its maintenance track record is still unproven.
The repository recorded zero commits and zero active maintainers in the last three months, which is concerning for a package whose release history already contains only one version.
The repository has zero stars and one fork. This is weak supporting evidence, but popularity alone does not outweigh the package's tests and documentation.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap rather than a decisive health problem.
The repository has no security policy, reducing the transparency of vulnerability reporting for a package that handles signed image-service URLs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.0|^7.0 | — | — |
symfony/http-kernel Version ^6.0|^7.0 | — | — |
symfony/dependency-injection Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.