The stable major release and organization-backed repository provide useful context. Install-time hooks, absent security scanning, and a very small source tree leave limited transparency for ongoing maintenance.
58%
Total Score
75
86
63
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution surface for adopters. Such hooks can be normal for a Symfony Flex skeleton, but they still warrant more scrutiny than a package without install-time behavior.
The artifact and linked repository each contain only composer.json, leaving almost no visible documentation or source context for consumers to inspect.
The package has 34 releases since April 2019, but none in the last 12 months; its latest release was about 19 months before collection. This indicates a mature history but currently inactive release maintenance.
The repository had zero commits and zero active maintainers in the last three months. Combined with no registry releases in the last year, this points to stalled current maintenance.
Composer is used as the build tool, but no security scanning tool is reported. This is a modest transparency and maintenance gap rather than evidence of an unsafe package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.