Symfony integration of Cooper: bundle configuration and container parameters from a CASC document, ${NAME} kept a runtime %env()% placeholder, .env files read by Cooper.
68%
Total Score
caution
A first release with no commits yet and entirely unpinned workflow actions leaves maintenance and build integrity unproven.
The package and repository are owned by the same individual account, so the source appears aligned with the publisher, but there is no organization backing shown to broaden maintenance capacity.
This is the package's first release, published today, so there is no release track record yet; the very recent repository activity partly fits that early stage but does not establish durability.
There were no commits and no active maintainers in the last three months. Because the package is only one day old, this is limited evidence rather than proof of abandonment, but it leaves maintenance capacity unestablished.
Four pull requests were opened in the last month, showing some activity, but none were merged; this provides only weak compensation for the absent recent commit activity.
No repository security policy was found. This is a transparency gap, but the repository does provide automated dependency scanning, which partly compensates for the missing policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 || ^7.0 || ^8.0 | — | — |
joetjen/cooper Version ^0.1 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/runtime Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.