This release appears suitable to depend on, with strong repository and packaging hygiene: it is MIT-licensed, non-deprecated, actively released, backed by an organization-owned repository, and supported by tests, a changelog, CI, security policy, Dependabot, and recent commit and pull-request activity. The package is relatively young at 35 days old and has a substantial runtime dependency set, while workflow permission declarations are incomplete and one pull-request-target workflow warrants review, so it is healthy overall but not without supply-chain and maturity considerations.
82%
Total Score
100
50
94
80
One of five workflows uses pull_request_target, which can require careful handling of untrusted pull-request input; however, no untrusted checkout or script-injection pattern was detected.
The package declares 12 runtime dependencies, including multiple Symfony and Nowo.tech components; this adds dependency-surface and compatibility complexity, though the profile is coherent with a feature-rich Symfony bundle.
The package has 13 releases in 35 days with a median interval of about 1.3 days, showing active iteration but limited historical maturity.
Four workflows lack top-level permission declarations and one workflow requests top-level write access, leaving avoidable ambiguity in CI token privileges despite job-level permissions being present elsewhere.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 || ^4.0 | — | — |
symfony/config Version ^7.0 || ^8.0 | — | — |
endroid/qr-code Version ^6.0 | — | — |
twig/extra-bundle Version ^3.12 | — | — |
twig/string-extra Version ^3.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.