The package has a strong release cadence, repository activity, tests, and clear licensing. It lacks a security policy, and its single workflow uses one unpinned action, leaving minor maintenance and automation gaps.
86%
Total Score
100
100
89
67
The repository reports zero stars and forks, with eight watchers. This limits popularity evidence but does not outweigh the strong release and maintenance signals.
Composer is used for the build, but no security-scanning tooling is reported. This is a minor transparency gap rather than evidence of abandonment.
The repository has no security policy. For a reusable library this weakens the documented vulnerability-reporting process, though active releases and repository tests partly compensate.
The only workflow was fully analyzed with no dangerous audit findings or untrusted checkout/script-injection sinks. However, its one action use is unpinned, which is a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version 7.4.* | — | — |
symfony/string Version 7.4.* | — | — |
symfony/html-sanitizer Version 7.4.* | — | — |
symfony/options-resolver Version 7.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.