It has a clear README, a stable v3 release, and no install-time scripts. Composer tooling and automated security scans are present, but the repository has no security policy and its workflows use unpinned container images.
60%
Total Score
83
100
89
67
The package has seven releases since March 2019, but none in the last 12 months and the latest was over two years ago, which raises maintenance concerns.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is a meaningful abandonment concern.
The repository has no stars or forks and only four watchers, indicating limited community adoption; this is supporting evidence rather than a health verdict.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Both workflows use read-only permissions and the audit completed fully, but both contain high-confidence unpinned container images, reducing build reproducibility and increasing workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.4 | — | — |
symfony/console Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.