Clear documentation, tests, and organizational ownership support the package. Build hygiene is weaker because all six workflow actions are unpinned and no security policy is present.
68%
Total Score
83
88
83
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowing maintenance despite a recent package release and repository push.
Composer build tooling is present, but no security scanning tools were detected, leaving an avoidable transparency and maintenance gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear.
Version 0.1.8 is not a stable-major release, so API compatibility may still evolve, although it is not marked as a prerelease and recent prerelease share is zero.
All six analyzed GitHub Actions references are unpinned, which weakens build reproducibility and supply-chain hygiene. The workflow has no untrusted checkout or script-injection findings, and its missing top-level permissions block is not a concern by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.4 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 | — | — |
dbp/relay-core-bundle Version ^0.1.181 | — | — |
dbp/relay-verity-bundle Version ^0.2.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.