Symfony bundle which contains tools that can be used to check whether the current runtime environment is set up as expected.
68%
Total Score
caution
Usable with caveats: no registry release in 18 months despite recent repository activity.
A post-install command runs during installation, adding execution during dependency setup and a modest supply-chain hygiene concern.
Only two releases have been published, with no registry release in the last 12 months; the latest release was about 18 months ago. Recent repository work partly offsets the stale registry cadence but does not remove adoption risk.
The repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is not clearly established.
The repository has no security policy, leaving vulnerability-reporting expectations and response instructions unclear.
All five workflows were analyzed with no injection or high-severity findings, but all four analyzed action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.3 || ^7.0 | — | — |
symfony/yaml Version ^6.3 || ^7.0 | — | — |
symfony/config Version ^6.3 || ^7.0 | — | — |
monolog/monolog Version ^3.6 | — | — |
symfony/process Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.