Its README and small dependency set make integration straightforward. There are no tests or security tooling, and only two commits from one contributor so far.
55%
Total Score
50
75
50
The manifest declares a proprietary license, with no detected license text or license file. For an open-source dependency, this creates a meaningful adoption and redistribution concern.
The package is only 44 days old and has two releases, both published within the same day. This is too little history to demonstrate sustained maintenance, though it is not evidence of abandonment by itself.
All two recent commits came from one contributor, leaving maintenance dependent on a single person. No organizational backing is shown to compensate for that concentration.
The repository recorded only two commits in the last three months, all within a very new project. This provides limited evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/validator Version * | — | — |
symfony/http-foundation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.