Tests, static analysis, and a clear license support day-to-day use. Install scripts and the absent security policy add operational caveats.
72%
Total Score
75
100
50
post-install-cmd and post-update-cmd scripts run during Composer operations, adding install-time behavior that consumers should account for.
One contributor made all 8 commits in the last 3 months, creating a meaningful continuity risk for a user-owned project.
The repository has no SECURITY.md policy, which reduces transparency around vulnerability reporting and response expectations.
The single workflow is fully analyzed, uses read-only permissions, and has no reported dangerous findings; however, all 5 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
symfony/flex Version ^2.5 | — | — |
symfony/form Version ^8.1 | — | — |
symfony/mime Version ^8.1 | — | — |
symfony/yaml Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.