Usable with caveats: this is a mature, actively released Symfony bundle with clear documentation, tests in the repository, and a recent release. However, the repository recorded no commits or active maintainers in the last three months, and it lacks a security policy.
68%
Total Score
75
50
100
80
The package has 16 runtime dependencies, including Symfony components and the GraphQL implementation it integrates with; this is a meaningful but coherent dependency surface for a framework bundle.
The repository recorded zero commits and zero active maintainers in the last three months. A release during the broader period is compensating evidence, but the lack of recent development activity still raises maintenance concerns.
There was one new pull request in the last month but no issues or pull requests were closed, while 115 issues and 25 pull requests remain open; this suggests limited recent project throughput.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented for a security-sensitive server integration.
The only workflow lacks top-level token permissions. No write permissions were observed, but the permissions are not explicitly constrained, which is a modest workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/config Version ^5.4.46 || ^6.4.32 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^5.4.50 || ^6.4.32 || ^7.0 || ^8.0 | — | — |
webonyx/graphql-php Version ^15.24 | — | — |
symfony/http-foundation Version ^5.4.50 || ^6.4.32 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.