Lean continuous improvement for Symfony applications
68%
Total Score
caution
A well-documented first release, but it has no established maintenance history and uses two unpinned GitHub Actions.
This is the package's first release, published today, so there is no historical release cadence or evidence of sustained maintenance yet. That is a meaningful maturity gap, though it is expected for a newly launched package.
The repository records zero commits and zero active maintainers in the last three months. Because the package was released today, this mainly shows that a sustained maintenance history has not yet been demonstrated.
The repository has zero stars, forks, and watchers. For a package released today this is unsurprising, but it provides no supporting evidence of community maturity.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a modest repository hygiene gap, not evidence that the package is unsafe.
The workflow audit completed fully, found no high- or medium-severity findings, and confirms read-only permissions. However, both of the two analyzed action references are unpinned, leaving them exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
symfony/twig-bundle Version ^7.4 || ^8.0 | — | — |
symfony/security-csrf Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.