The MIT license, README, and repository tests provide useful basics. A single publisher, no security policy or scanning, and a small repository with no community activity leave limited independent assurance.
68%
Total Score
50
50
88
75
Thirteen runtime dependencies, including framework and extension requirements, create a relatively broad dependency surface; no compensating development-only separation is shown because dev dependencies total zero.
Only one registry maintainer account is listed, which limits publishing redundancy; the linked repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this.
The repository recorded zero commits and zero active maintainers in the last three months, despite the registry showing 44 releases in the last year; this weakens confidence that source maintenance matches release activity.
The repository has zero stars and forks and one watcher, providing little evidence of external adoption or review. Popularity is supporting evidence, so this is a modest concern rather than a severe risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository-hygiene gap without making the release unfit by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version 6.4.* | — | — |
snc/redis-bundle Version ^4.8 | — | — |
symfony/test-pack Version ^1.1 | — | — |
symfony/serializer Version 6.4.* | — | — |
symfony/http-client Version 6.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.