High-performance asset handling for symfony projects.
62%
Total Score
75
100
93
67
The package has 25 releases since 2017, but none in the last 12 months and the latest registry release was in January 2023. This indicates a substantial release-maintenance gap despite the earlier regular cadence.
The repository recorded no commits and no active maintainers in the last 3 months. Although its recent push timestamp shows repository activity of some kind, the observed commit window does not demonstrate ongoing development.
The linked repository has no security policy. That is a transparency and vulnerability-reporting gap, though it does not by itself show that the package is unsafe.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, but both of its two action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a build-integrity hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0.1 || ^2.0.0 || ^3.0.0 | — | — |
twig/twig Version ^3.3.8 | — | — |
symfony/mime Version ^5.4.3 || ^6.0.3 | — | — |
symfony/config Version ^5.4.3 || ^6.0.3 | — | — |
symfony/finder Version ^5.4.3 || ^6.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.