This is a healthy, mature release with a long release history, frequent recent publishing, stable versioning, an active and non-archived organization-backed repository, repository tests, security policy, dependency scanning, and no install-time lifecycle scripts. The main reservations are that recent commits are concentrated in one contributor and all analyzed workflows lack top-level token-permission declarations, which are hygiene concerns rather than evidence of abandonment or an unfit release. The available evidence supports depending on version 2.17.1, subject to normal compatibility and security review.
91%
Total Score
90
100
100
90
Four contributors were active in the last 3 months, but the top contributor made 10 of 13 commits, or about 77%, creating some concentration risk. The organization-backed repository and activity from three additional contributors partly mitigate this concern.
All eight analyzed workflows lack top-level permissions declarations. Although none declares top-level write permissions, the absence of explicit least-privilege defaults is a workflow hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
mongodb/mongodb Version ^1.21.2 || ^2.1.1 | — | — |
symfony/console Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/var-dumper Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
doctrine/collections Version ^2.1 || ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.