The project has a long history, tests, release notes, and recent repository activity. Its only active contributor, missing security policy and scanning, and three unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
70%
Total Score
50
86
75
The package has existed for about 9 years with 12 releases, but only one release in the last 12 months and a median interval of about 358 days indicate slow maintenance cadence.
One contributor made 100% of the recent commits, leaving maintenance highly dependent on a single person.
There was one commit in the last three months from one active maintainer, which shows recent activity but only limited ongoing maintenance capacity.
Composer is used for builds, but no security scanning tools were detected, leaving supply-chain hygiene less transparent.
The repository has no security policy, so its process for receiving and documenting vulnerability reports is unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.4||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.