Clear documentation, tests, licensing, and a matching repository make integration and ownership transparent. The small release history and limited recent commit activity leave less evidence of long-term maintenance. Workflow checks are complete but use two unpinned actions, and no security policy is published.
68%
Total Score
80
100
81
83
One registry publisher is consistent with this user-owned project, but it provides limited publishing redundancy.
Only two releases have been published over about 103 days, with the latest roughly 77 days after the assessment window's start; this is a young project with limited history for judging durable maintenance.
Only two commits were recorded in the last three months, so recent maintenance capacity is present but limited.
Composer is used for builds, but no security scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-kernel Version ^6.4|^7.0|^8.0 | — | — |
symfony/dependency-injection Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.