The package has a clear MIT license, useful documentation, repository tests, and a release note covering PHP 8.4. Its workflows use unpinned actions, and the project lacks both a security policy and security-scanning tools.
61%
Total Score
50
88
50
Only two releases exist across about two years, with no releases in the past year. This points to a slow maintenance cadence, though the latest release added PHP 8.4 support.
The repository recorded zero commits and zero active maintainers in the past three months. The repository was updated for the assessed release, but current maintenance activity is absent.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy. That leaves vulnerability reporting and maintainer response expectations undocumented.
All three workflows were analyzed successfully and showed no dangerous triggers or audit findings, but all 9 action references are unpinned. The workflows also omit top-level permissions blocks, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^4.4|^5.4|^6|^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.