The repository has no security policy and does not mention this package in its README, reducing transparency. MIT licensing and organization ownership provide useful context, but ongoing support remains uncertain.
58%
Total Score
75
86
75
The package has six releases since May 2023, but none in the last 12 months and the latest release was in March 2025. This indicates a meaningful maintenance slowdown for a dependency, though the release history is not extremely short.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of ongoing maintenance, although a small stable package may not require frequent changes.
The repository name does not match the package name and its README does not mention the package. Although the linked repository is under the same organization, this mismatch makes package ownership less transparent.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, but it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/notifier Version ^6.4|^7.2 | — | — |
symfony/http-client Version ^6.4|^7.2 | — | — |
symfony/framework-bundle Version ^6.4|^7.2 | — | — |
giggsey/libphonenumber-for-php Version ^8.13 | — | — |
fagforbundet/notification-api-client-bundle Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.