This release has strong transparency and engineering hygiene: it is MIT-licensed, includes tests, a changelog, extensive documentation, a substantial source tree, security policy, dependency scanning, and workflows without the analyzed dangerous patterns. It is not deprecated or archived, and the repository matches and documents the package. However, the project is only 1 day old, has released 9 versions in a very short period, remains on an unstable 0.x major line, has no recorded commits or active maintainers in the last 3 months, and has no observed community traction; these are meaningful maturity and continuity risks for a dependency. Overall it appears usable but too new to rate as fully healthy, so adoption should include normal version pinning and review of future maintenance.
72%
Total Score
50
100
83
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.