The package is clearly licensed, tested, and published from a matching organization repository. Its small scope and release notes reduce the impact of the maintenance gap.
64%
Total Score
75
90
50
The latest release was about two years ago, with no releases in the last 12 months and seven releases overall. This indicates a maintenance gap, though the package may be stable and narrowly scoped.
The repository had no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance. The repository is not archived and the package has a recent documented release, partly offsetting the concern.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version ^6.0|^7.0 | — | — |
symfony/http-foundation Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.