Workflow dependencies are not pinned, and the release workflow installs a package outside a lockfile. The project has tests, release notes, an MIT license, and organization backing, but no security policy or scanning evidence.
58%
Total Score
63
100
83
63
The repository recorded zero commits and zero active maintainers in the last three months, consistent with about nine months since the last push and raising maintenance risk.
Post-install and post-update Composer scripts add execution during dependency operations, creating a modest supply-chain exposure that warrants review.
All six releases arrived within four days, showing strong initial activity but too little history to establish a durable maintenance pattern.
There are no open issues or pull requests and no activity in the last month, which offers no evidence of an active user or contributor community.
The repository has no stars, forks, or watchers, providing no external adoption evidence; this is supporting context rather than a health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/mime Version ^7.0 | — | — |
symfony/http-client Version ^7.0 | — | — |
symfony/framework-bundle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.