The package is licensed, documented, stable, and backed by repository tests and release notes. Recent work is concentrated in one contributor, and the repository lacks a security policy and security scanning, so maintenance resilience and transparency are limited.
78%
Total Score
83
100
94
80
All 14 recent commits came from one contributor, leaving the project vulnerable if that person becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and detection gap for a security-focused bundle.
The repository has no security policy, making vulnerability-reporting expectations and response procedures less clear.
Two workflows lack top-level permissions and one workflow declares top-level write access, which is weaker workflow permission hygiene than a consistently least-privilege setup.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-foundation Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/event-dispatcher Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/service-contracts Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.