The package includes tests, a changelog, release notes, and matching MIT licensing, while its organization-backed repository is active enough to publish a recent stable release. Workflow dependencies are unpinned, and no security policy or scanning tooling is present, so maintenance transparency is not ideal.
72%
Total Score
75
100
89
50
The repository recorded zero commits and zero active maintainers in the last three months. This is a maintenance concern, although the recent release provides some compensating evidence.
The repository has only 3 stars, no forks, and no watchers, indicating limited visible adoption. Popularity is supporting evidence, so this lowers confidence in project depth but does not make the package unsafe by itself.
Composer and Make are used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed without audit findings or untrusted code paths, but both action references are unpinned. The workflows also lack top-level permissions blocks, which is acceptable on its own but provides less explicit permission hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^7.4 || ^8.0 | — | — |
symfony/validator Version ^7.4 || ^8.0 | — | — |
symfony/translation Version ^7.4 || ^8.0 | — | — |
symfony/http-foundation Version ^7.4 || ^8.0 | — | — |
symfony/property-access Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.