Usable with caveats: it is a new v0.1.0 package with only one release and one active contributor, so long-term stability is unproven. The repository is active and well documented, with tests, a changelog, and a matching MIT license.
68%
Total Score
67
100
81
88
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
This package was released only once, on September 12, 2026, and has no established release interval or track record. That makes long-term maintenance and compatibility uncertain for a dependency.
All 27 recent commits came from one contributor, leaving a high single-person dependency and increasing abandonment risk if that contributor becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected. The lack of scanning is a transparency and maintenance gap, though it is not by itself evidence of unsafe code.
The repository has no security policy, so its process for reporting and handling vulnerabilities is unclear. This matters for a reusable web-framework bundle.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version >=6.4 | — | — |
symfony/validator Version >=6.4 | — | — |
symfony/http-kernel Version >=6.4 | — | — |
symfony/dependency-injection Version >=6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.