The project includes a license, README, tests, and a repository that clearly matches the package. Install and update scripts, together with no security policy or scanning tools, warrant extra care for this deployment template.
54%
Total Score
50
80
50
Composer post-install and post-update scripts run during package operations. Such scripts can be normal for a Symfony application skeleton, but they add execution surface during installation.
Only two releases were published, both within about 15 minutes on June 2, 2025, with no releases in the following 12 months. This indicates a young package whose maintenance has not been demonstrated over time.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the lack of recent release activity and increasing abandonment risk.
The repository uses Make and Composer, but no security scanning tools are present. This is a maintenance and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2 | — | — |
symfony/yaml Version 7.0.* | — | — |
symfony/dotenv Version 7.0.* | — | — |
symfony/console Version 7.0.* | — | — |
symfony/runtime Version 7.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.