This release appears healthy and reasonable to depend on: it is actively maintained, has 18 releases over 88 days, a stable non-prerelease version, a non-archived repository with 41 commits and 14 merged pull requests recently, tests, changelog, documentation, licensing, security policy, and Dependabot coverage. The main concerns are the very young project age, zero repository popularity metrics, concentration of commits among two contributors, and GitHub Actions permission/workflow-hardening gaps, including write permissions and untrusted checkout usage. These warrant normal dependency review and pinning, but do not outweigh the strong maintenance and project-structure evidence.
82%
Total Score
100
100
94
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.0 || ^8.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
symfony/http-kernel Version ^7.0 || ^8.0 | — | — |
symfony/twig-bundle Version ^7.0 || ^8.0 | — | — |
nowo-tech/qr-code-bundle Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.