Tests, a usable README, and an MIT license provide a reasonable starting point, while the organization-backed repository is not archived. The package has had no release or repository update for about two years and three months, with no security scanning or policy, so future compatibility and maintenance are uncertain.
45%
Total Score
100
78
83
Only two releases were published, both in July 2024, with no release in about two years and three months. This is strong evidence of stalled maintenance for a package developers may need to keep compatible with Symfony and AWS changes.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but this provides little independent evidence of broad use or review.
Composer is used for builds, but no security scanning tool is configured. This is a maintenance and transparency gap, though it does not by itself show that the package is unsafe.
The repository has no security policy. For a bundle that handles AWS SNS credentials, this reduces transparency about how vulnerabilities should be reported and handled.
Version 0.2 is not a stable major release, which adds compatibility uncertainty. The release is not marked as a prerelease, so this is a moderate concern rather than a severe one.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.3 | — | — |
symfony/yaml Version ^6.0 || ^7.0 | — | — |
symfony/config Version ^6.0 || ^7.0 | — | — |
aws/aws-sdk-php Version ^3.316 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.