A clear README, MIT declaration, and organization ownership improve day-to-day confidence. The project is young, with limited adoption evidence and no documented security process, so pin this version and monitor maintenance.
70%
Total Score
67
89
75
One contributor made all 12 commits in the last 3 months, creating a meaningful continuity risk despite the organization-owned repository.
There were 12 commits in the last 3 months, so work is continuing; however, the activity is concentrated in a very small contributor base.
The repository has zero stars, forks, and watchers, so there is no observed external adoption or review signal; this is supporting evidence only, not proof of poor quality.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest supply-chain hygiene gap.
No security policy is present, leaving vulnerability-reporting expectations unclear for a framework integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4|^7.0|^8.0 | — | — |
cognesy/agents Version ^2.11 | — | — |
symfony/config Version ^6.4|^7.0|^8.0 | — | — |
cognesy/logging Version ^2.3 | — | — |
symfony/messenger Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.