The package is licensed, documented, tested in the repository, and released frequently. Security policy coverage is absent, while recent work is concentrated in one contributor and the workflow uses an unpinned action.
72%
Total Score
75
100
94
75
One contributor made all recent commits, creating a concentrated bus factor. Organization backing partly offsets individual dependency, but it does not remove the risk of a single active maintainer.
Only two commits were recorded in the last three months, with one active maintainer. This is some recent activity, but the low volume indicates limited maintenance capacity.
Composer is used for builds, but no security-scanning tools were detected. The absence of scanning is a hygiene gap, not evidence that the package is unsafe or abandoned.
The repository has no security policy. That weakens vulnerability-reporting transparency, although active releases and organization ownership provide some compensating maintenance context.
The single workflow was fully analyzed with no detected injection or high-severity findings, and it has no top-level write permissions. Its one action is unpinned, which is a supply-chain hygiene weakness; the pull_request_target trigger has no untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version 7.4.* | — | — |
symfony/mailer Version 7.4.* | — | — |
symfony/console Version 7.4.* | — | — |
symfony/http-client Version 7.4.* | — | — |
symfony/twig-bundle Version 7.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.