The project has a small user-owned maintainer base and no recent commits, so future fixes may depend on one person. Clear documentation, tests, a recent release with notes, and an active repository offset that risk; workflow references still need pinning.
67%
Total Score
50
88
67
The registry namespace and repository belong to the same individual account, providing direct ownership alignment but no organizational backing to compensate for the small maintainer base.
The package has existed for 977 days with seven releases, but only one release in the last 12 months and a median interval of about 162 days indicate a slow cadence rather than active maintenance.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package that may need compatibility or security fixes.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/asset Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/config Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/validator Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/http-client Version ^5.4|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.