The repository has recent changes, but every commit in the last three months came from one automated account. All 10 workflow actions are unpinned, and no security policy or security scanning was found.
22%
Total Score
67
86
75
The registry marks the entire package as abandoned and names applogger/symfony-bundle as its replacement, making this release unsuitable for a new dependency despite other healthy signals.
The repository is owned by an individual rather than an organization, so the one-contributor concentration has no shown organizational handoff support.
One contributor made 100% of the 23 recent commits, concentrating maintenance entirely in a single account and increasing continuity risk.
The repository has no security policy, leaving disclosure and response expectations undocumented.
The single workflow was fully analyzed and has no dangerous triggers or audit findings, but all 10 action references are unpinned, weakening build reproducibility and action integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^6.4|^7.0|^8.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
applogger/sdk-core Version ^1.0 | — | — |
symfony/http-client Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-kernel Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.