The repository is still receiving commits, and the source includes tests and release notes. Maintenance is concentrated in one contributor, while all three workflow actions are unpinned and no security policy is provided.
70%
Total Score
75
93
67
The package has eight releases since July 2016, but none in the last three years; this indicates a slow release cadence, partly offset by recent repository activity.
One contributor made all four recent commits, leaving maintenance capacity highly concentrated and increasing continuity risk for a user-owned project.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all three referenced actions are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~6.1 | — | — |
symfony/validator Version ~6.1 | — | — |
symfony/http-kernel Version ~6.1 | — | — |
kiczort/polish-validator Version ^1.2 | — | — |
symfony/dependency-injection Version ~6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.