Consumer documentation and tests are present, and the release is clearly licensed. The project has organizational backing, but recent work is limited and its workflow dependencies are not pinned.
70%
Total Score
67
93
75
One contributor made all commits in the last three months. The organization-owned project provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, showing thin recent maintenance despite the recent release and repository update.
The project uses Make and Composer, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability-reporting expectations less clear for a dependency used in applications.
The workflow audit completed cleanly with no dangerous triggers or audit findings, but all 11 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.4||^6.0||^7.0 | — | — |
symfony/config Version ^5.4||^6.0||^7.0 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
symfony/http-kernel Version ^5.4||^6.0||^7.0 | — | — |
symfony/event-dispatcher Version ^5.4||^6.0||^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.