The bundle is documented, tested, licensed, and not deprecated, which supports adoption. Its single release and no commits in the past three months leave maintenance maturity uncertain, while missing security scanning and unpinned workflow actions add hygiene concerns.
58%
Total Score
50
78
75
The repository is owned by a user account rather than an organization, so the available ownership context does not show institutional backing to offset the thin maintenance record.
This package is about five months old but has only one release, so there is little release history from which to judge sustained maintenance.
The repository recorded no commits and no active maintainers in the past three months, a meaningful sign that maintenance may have stalled after the initial release.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, but it offers no external maturity signal for this very new package.
Composer build tooling is present, but no security scanning tools were detected, leaving automated dependency or code-security checks unconfirmed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.0 | — | — |
endroid/qr-code Version ^5.0 | — | — |
symfony/http-client Version ^7.0 | — | — |
spomky-labs/cbor-php Version ^3.0 | — | — |
symfony/security-bundle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.