Symfony bundle to react to the deploy and undeploy of a project.
66%
Total Score
caution
Usable with caveats: sparse releases, no recent commits, and unpinned workflow actions weaken maintenance confidence.
A post-install-cmd script runs during installation, which expands install-time behavior and warrants inspection even though this signal alone does not show that it is unsafe.
Only two releases have appeared over about 27 months, with one release in the last 12 months and a roughly 20-month median interval. This suggests a slow-moving project, though the recent 1.1.0 release provides some evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the preceding three months. This conflicts somewhat with the recent repository push and release evidence, but still lowers confidence in sustained development activity.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent than expected. The organization-backed repository and package-specific source tree partly reduce that concern, but do not remove it.
No security policy was found in the repository. This is a modest transparency gap for reporting vulnerabilities, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.3 || ^7.0 | — | — |
symfony/config Version ^6.3 || ^7.0 | — | — |
symfony/messenger Version ^6.3 || ^7.0 | — | — |
symfony/http-kernel Version ^6.3 || ^7.0 | — | — |
symfony/framework-bundle Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.