Usable with caveats: the package is licensed, documented, tested, actively released, and backed by a matching repository. However, the repository has had no commits in the last three months, has only one registry maintainer, and lacks a security policy.
68%
Total Score
50
100
94
63
The repository recorded zero commits and zero active maintainers during the last three months. Although a release was published recently, the absence of sustained commit activity raises maintenance risk.
A post-autoload-dump install script runs during Composer operations. This is not inherently unsafe, but it adds install-time behavior that should be reviewed before adoption.
Only one account has registry publishing access. The matching user-owned repository provides some continuity, but a single publisher leaves limited redundancy if that maintainer becomes inactive.
There is one open issue and one open pull request, with no issues or pull requests opened or closed in the last month. This indicates limited current community activity.
The repository has six stars and one fork. This is limited adoption evidence, but popularity is supporting evidence rather than a decisive health measure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.2 | — | — |
psr/simple-cache Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.