The package includes tests, documentation, a license, and no install-time scripts. Its organization-backed project has had no recent issue or commit activity, while workflow dependencies are unpinned and no security policy is present.
42%
Total Score
50
75
67
The package has had 16 releases since 2015, but none in the last 12 months; the latest registry release was about six years ago. This strongly suggests abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since its last push. This materially lowers confidence in ongoing maintenance.
There were no new or closed issues or pull requests in the last month, with one issue and one pull request still open. This provides no evidence of active support.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it does not by itself show unsafe code.
Both workflows were fully analyzed with no detected injection or dangerous-trigger findings, but all four referenced actions are unpinned. The missing top-level permissions blocks are acceptable on their own, while unpinned actions remain a modest reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.0 | — | — |
symfony/config Version ^5.0 | — | — |
symfony/validator Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/http-foundation Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.