Healthy and suitable to depend on. It has frequent releases, active organization backing, recent contributions from four maintainers, and clear repository/package alignment; the main caveat is concentrated commit activity and limited workflow hardening.
86%
Total Score
83
94
67
The repository has one pull_request_target workflow, which can require careful handling of untrusted pull requests; no untrusted checkout or script injection was detected, limiting the concern.
One contributor made 75% of the recent commits, creating some concentration risk, although three additional contributors were active and the organization-backed project can hand work off.
Composer is used for builds, but no repository security-scanning tools were detected, leaving a modest transparency and preventive-maintenance gap.
The workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege declarations would provide stronger workflow hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/web-link Version ^7.4 || ^8.0 | — | — |
symfony/type-info Version ^7.4 || ^8.0 | — | — |
api-platform/state Version ^5.0 | — | — |
api-platform/jsonld Version ^5.0 | — | — |
api-platform/metadata Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.