Usable with caveats: this is a very new package with only two releases and limited repository history. It has clear licensing, tests, documentation, safe workflows, and a balanced two-contributor record, but lacks a security policy and has broadly undeclared workflow token permissions.
72%
Total Score
70
100
94
80
Only one registry account has publish access, which is a continuity risk for a user-owned project, though repository activity shows a second recent contributor.
The registry namespace and repository owner match, but both belong to a user account rather than an organization, so there is no organizational succession signal.
The package is only hours old and has two releases, so there is not yet enough release history to demonstrate sustained maintenance or long-term stability.
Two commits from two active maintainers in the last three months show recent work, but the extremely small history provides limited evidence of sustained maintenance.
No security policy is present, leaving vulnerability-reporting and response expectations undocumented for users of this reusable library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.