The package is licensed, documented, and backed by an organization. Its workflow is basic and lacks security scanning, so maintenance transparency is good but automation hygiene is only moderate.
84%
Total Score
100
50
94
67
The release declares 34 runtime dependencies, including several framework and extension requirements. That increases integration and update complexity, though it is consistent with a substantial core bundle.
Composer is used as a build tool, but no security scanning tool is reported. The absence of scanning is a modest transparency gap, not evidence of abandonment.
The repository has no security policy. This weakens the project's documented vulnerability-reporting process, although active releases and organizational backing partly compensate.
All workflows were analyzed and no audit findings or untrusted checkouts were reported. However, the single workflow has one unpinned action and no top-level permissions block, leaving minor automation-hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.7.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/form Version 7.4.* | — | — |
symfony/ldap Version 7.4.* | — | — |
symfony/asset Version 7.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.