Usable with caveats: this is a licensed, stable release from an organization-backed repository that was updated with the release. Maintenance evidence is thin, with only one recent commit from one contributor and no security policy or scanning tools.
72%
Total Score
67
100
94
75
All recent commit activity comes from one contributor, creating a meaningful continuity risk; organization backing provides some capacity to hand maintenance off but does not demonstrate that a second contributor is active.
The repository recorded only one commit in the last three months, showing some recent activity but a very limited maintenance cadence.
Composer is used as the build tool, but no security scanning tools are configured, leaving a security-maintenance gap in the repository.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 || ^7.4 | — | — |
symfony/cache Version ^6.4 || ^7.4 | — | — |
symfony/finder Version ^6.4 || ^7.4 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.4 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.