Generate changelogs and release notes from a project's commit messages and metadata and automate versioning with semver.org and conventionalcommits.org
72%
Total Score
caution
Usable with caveats: one contributor carries recent maintenance, with some workflow and install-script exposure.
The package runs post-install and post-update Composer scripts. These scripts are not inherently unsafe, but they increase install-time behavior that dependents should understand.
Only one registry account has publish access, matching the user-owned repository. Recent repository activity shows that the maintainer is active, but publication and maintenance are still concentrated in one person.
The repository is owned by a user rather than an organization, so the one-person maintenance concentration is not backed by an organization-level handoff path. The owner is active, which prevents this from being a severe risk.
One contributor made all 12 commits in the last 3 months, giving the project a single-person operational dependency. The recent activity is healthy, but a maintainer absence could slow fixes.
The repository has no published security policy. This is a transparency gap for reporting vulnerabilities, though it is partly offset by the repository's security scanning tooling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.4 || ^4 || ^5 || ^6 || ^7 || ^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.