Clear documentation, a permissive license, and repository tests support adoption. Rapid releases and a stable version help, but install-time scripts and limited security process add maintenance overhead.
67%
Total Score
50
100
94
50
post-install-cmd and post-update-cmd scripts run during dependency operations, adding supply-chain and installation behavior that consumers must account for.
One contributor made all commits in the last three months, leaving maintenance dependent on a single active developer.
Only one commit was recorded in the last three months, indicating limited recent development activity despite the active release history.
Composer build tooling is present, but no security scanning tools were detected, leaving security-process coverage limited.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/validator Version ^7.4|~8.0.14 | — | — |
symfony/serializer Version ^7.4|^8.1.1 | — | — |
symfony/http-foundation Version ^7.4|^8.1.1 | — | — |
symfony/event-dispatcher Version ^7.4|^8.1.1 | — | — |
symfony/framework-bundle Version ^7.4|^8.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.