Build tooling, repository tests, and security reporting provide useful transparency. The project is young and its workflow actions are unpinned, while maintenance remains concentrated but includes a second active contributor.
80%
Total Score
83
100
94
67
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution surface for consumers even though no other signal indicates harmful behavior.
The package is only 58 days old but has 26 releases, with a median interval of about 21 minutes. This shows active publishing, though the unusually rapid cadence leaves less long-term stability evidence.
Two contributors were active in the last three months, but the top contributor made about 73% of commits. The second contributor provides some continuity, while ownership remains concentrated.
The single workflow was fully analyzed, uses read-only permissions, and has no detected injection or high-severity findings. However, all 3 action references are unpinned, leaving avoidable build reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-php83 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.