This is a healthy, actively maintained Symfony integration package with a strong release cadence, a stable non-prerelease version, complete basic project documentation and testing scaffolding, and a recently updated, non-archived organization-owned repository. The main concerns are that 83% of recent commits come from one contributor, the repository has no security policy, and its CI workflow declares no top-level token permissions. These are meaningful hygiene and continuity risks, but they are outweighed by 24 commits from four contributors in the last 3 months, 36 releases in the last 12 months, active pull-request merging, and the organization backing. It appears reasonable to depend on, with normal review of its relatively broad runtime dependency set.
85%
Total Score
90
50
94
80
The package declares 28 runtime dependencies, including a broad Symfony and 21TORR component set; this increases transitive maintenance surface, although it is consistent with a feature-rich Symfony bundle.
The leading contributor made 20 of 24 recent commits, an 83% share, creating concentration and continuity risk; three additional contributors remain active, and organization ownership provides some ability to hand off maintenance.
Composer build tooling is present, but no security-scanning tools were detected; the missing automated security tooling is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; this is a genuine security-maintenance hygiene gap.
The only workflow, .github/workflows/ci.yml, declares no top-level token permissions. Although no top-level write permissions were detected, explicit least-privilege configuration would provide stronger CI transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
21torr/cli Version ^1.3 | — | — |
21torr/snail Version ^1.0.2 | — | — |
symfony/lock Version ^8.0 | — | — |
21torr/hosting Version ^4.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.