This release is usable but warrants caution. It is a stable, non-deprecated package with a clear MIT declaration, matching repository, tests, and an organization-backed source repository, and it was released very recently. However, the repository shows no commits or active maintainers in the last three months, only one release in the last 12 months, negligible adoption signals, no security policy or security scanning, and no changelog. The repository README also identifies it as a read-only subtree whose issues should go to an upstream project, so maintenance may depend on activity outside this repository. Overall, the package is not evidently abandoned or unfit, but its thin direct maintenance and security transparency make it a moderate-risk dependency.
68%
Total Score
75
50
83
90
The package declares 8 runtime dependencies, including its client library and several Symfony components; this is a meaningful dependency surface but is reasonable for a Symfony integration bundle.
The package has existed for about 3 years and 5 months with 9 releases, but only 1 release in the last 12 months indicates relatively slow release activity despite the current release being recent.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. Although the latest release and push are recent, the lack of recent development activity raises maintenance and abandonment concerns.
There are no open issues or pull requests and no issue or pull-request activity in the last month; this is neutral for a small read-only subtree but provides little evidence of an active support community.
The repository has 0 stars and 2 forks, indicating very limited visible adoption; popularity is supporting evidence rather than a standalone disqualifier, but it reduces confidence in community resilience.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.4|^5.4|^6.4|^7.2 | — | — |
symfony/config Version ^4.4|^5.4|^6.4|^7.2 | — | — |
linkorb/spicedb-php Version ^1.1 | — | — |
symfony/http-kernel Version ^4.4|^5.4|^6.4|^7.2 | — | — |
symfony/security-core Version ^4.4|^5.4|^6.4|^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.