The package is well documented, tested, licensed, and has security scanning in place. Its main concern is that repository commits and active maintainers both fell to zero over the last three months, while workflow actions are unpinned.
62%
Total Score
50
50
94
67
The bundle declares 15 runtime dependencies, mostly aligned Symfony components plus PSR logging. This is a meaningful dependency surface for a young package, but it is coherent with the bundle's framework integrations.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so this represents a genuine continuity and bus-factor concern.
The registry namespace and repository owner match, but both are tied to an individual account rather than an organization. This supports ownership clarity but not broader maintenance capacity.
The repository recorded zero commits and zero active maintainers during the last three months. Although the release history shows earlier activity, the recent pause increases maintenance and abandonment risk.
No repository security policy was found. This is a transparency gap for a bundle handling consent and audit-log integrations, though GitGuardian provides some security coverage.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/asset Version ^8.0 | — | — |
symfony/config Version ^8.0 | — | — |
symfony/console Version ^8.0 | — | — |
symfony/http-kernel Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.