The package includes consumer documentation, release notes, and security tooling, with two recent contributors sharing work. Organization backing and frequent releases support continued maintenance.
80%
Total Score
100
100
94
67
The artifact includes GPL-2.0 license files, but the manifest declares a proprietary license; that mismatch creates avoidable licensing uncertainty despite the repository also carrying license files.
The package runs post-install and post-update Composer scripts, which increase installation complexity and supply-chain exposure, although this is a normal pattern for a Symfony application skeleton.
All three workflows were analyzed without untrusted checkouts or script-injection sinks, but high-confidence findings report broad GitHub App access and a reusable workflow inheriting secrets; template-injection findings remain hygiene concerns without a dangerous trigger.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ibexa/oss Version 5.0.10 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version 7.4.* | — | — |
symfony/dotenv Version 7.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.