Clear licensing, documentation, release notes, and repository alignment make this a transparent package. Workflow references are all unpinned, and the repository has no security policy, but the project is not archived and released this version recently.
76%
Total Score
75
94
83
There were no commits from active maintainers in the last 3 months, which is a maintenance concern, although a recent release and merged pull request provide compensating evidence of current project activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no documented security policy, making vulnerability reporting and response expectations less clear.
The sole workflow was fully analyzed and has no untrusted checkouts or script-injection findings, but all 10 action references are unpinned and the audit reports high-confidence template-injection findings; without a dangerous trigger these remain workflow hygiene concerns rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
jwilsson/spotify-web-api-php Version ^6.0 || ^7.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.