The package is clearly licensed, documented, and tied to a matching source repository with release notes. Its workflows use unpinned actions, one audit file failed, and the recent maintenance record is quiet; these warrant checking before adoption.
58%
Total Score
75
100
88
67
Only one release was published in the last 12 months, despite a much shorter historical median release interval, indicating a substantial slowdown in delivery.
The repository recorded zero commits and zero active maintainers in the last three months, which is a clear recent-maintenance concern.
The repository has zero stars and forks and one watcher, indicating limited external adoption; this is supporting caution rather than a verdict by itself.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities, although this is a secondary concern for the score.
Both workflow action references are unpinned, and one workflow file failed the audit, so the result is incomplete and reproducibility is weaker. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not dangerous on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4 | ^7.0 | ^8.0 | — | — |
symfony/finder Version ^6.4 | ^7.0 | ^8.0 | — | — |
symfony/string Version ^6.4 | ^7.0 | ^8.0 | — | — |
symfony/validator Version ^6.4 | ^7.0 | ^8.0 | — | — |
symfony/filesystem Version ^6.4 | ^7.0 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.