The package has a substantial README, tests, changelog, release notes, and a permissive license. Its organization-backed repository is intact, but the workflow setup has avoidable publishing and dependency-installation weaknesses.
60%
Total Score
75
100
88
67
Composer install and update lifecycle scripts run during dependency operations, adding execution surface for consumers. No provided evidence shows that these scripts are harmful, so this is a limited concern.
The package made 18 releases in a short burst, but the latest release was about nine months ago and the cadence is not sustained. This raises maintenance uncertainty without proving abandonment.
There were no commits and no active maintainers in the last three months, consistent with roughly nine months since the last observed push. This is the clearest maintenance risk for a package intended for ongoing use.
There were no new or closed issues or pull requests in the last month and no open work. This may reflect a small or quiet project, but it provides little evidence of ongoing support.
Composer build tooling is present, but no security scanning tools were detected. The missing scanner is a transparency and process gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/http-client Version ^7.0 | — | — |
symfony/framework-bundle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.