The repository has no commits or active maintainers in the last 3 months, while its lone workflow leaves both actions unpinned. MIT licensing, a matching repository, and security scanning provide useful transparency, but the 0.x release line remains less stable.
61%
Total Score
50
80
50
The repository recorded zero commits and zero active maintainers during the last 3 months. That is a meaningful maintenance and abandonment concern for a package intended for production Symfony applications.
Four releases arrived within roughly two months, but no newer registry release is shown after December 2025 despite the package being about 11 months old. This suggests maintenance may have slowed.
No security policy is present in the repository. This is a transparency gap for an integration handling reCAPTCHA and request metadata, although it does not by itself make the release unfit.
Version 0.2.0 is a stable, non-prerelease release, but it remains before 1.0, so breaking changes between minor versions are more likely.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive permissions, but both of its two action references are unpinned. That leaves avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/form Version ^7.0 || ^8.0 | — | — |
symfony/validator Version ^7.0 || ^8.0 | — | — |
symfony/http-client Version ^7.0 || ^8.0 | — | — |
symfony/framework-bundle Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.