The project has a small audience and limited security-process coverage. Clear documentation, tests, licensing, and two active contributors provide useful support, but workflow permissions and action pinning need tightening.
70%
Total Score
83
100
75
67
The package is only 41 days old with four releases, although releases have continued at roughly two-week intervals. This shows active development but limited maturity.
One contributor made 90% of the recent commits, creating concentration risk. The organization-owned project and a second active contributor partly compensate for that concentration.
The repository has zero stars, forks, and watchers. This is weak supporting evidence and lowers confidence in outside adoption, but it does not outweigh the observed maintenance activity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a security-process gap, not evidence that the package is unsafe.
The repository has no security policy. For a package that executes refactoring workflows, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-mate Version ^0.13 || ^0.14 || dev-main | — | — |
symfony/process Version ^6.4|^7.0|^8.0 | — | — |
matesofmate/common Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.