A long release history, current release notes, and useful documentation show a mature project with clear integration guidance. The small maintainer base, absent security policy, and loosely pinned workflow actions leave meaningful maintenance and build-integrity gaps.
68%
Total Score
50
94
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete sign that ongoing maintenance may have slowed despite the recent release.
There were no newly opened or closed issues or pull requests in the last month, while 21 issues remain open. Combined with the lack of recent commits, this weakens evidence of active support.
Composer is used for builds, but no security-scanning tool is present. That leaves a transparency and preventive-maintenance gap, though it is not severe on its own.
The repository has no published security policy. For a file-management bundle handling uploads and private folders, this makes vulnerability reporting and response less transparent.
Both workflows were analyzed without audit failures or dangerous triggers, but all four action references are unpinned. This is a workflow supply-chain hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.3 | — | — |
symfony/form Version ^6.0||^7.0||^8.0 | — | — |
symfony/mime Version ^6.0||^7.0||^8.0 | — | — |
symfony/asset Version ^6.0||^7.0||^8.0 | — | — |
symfony/string Version ^6.0||^7.0||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.