This release appears suitable to depend on, with a clear MIT license, a matching and actively updated source repository, tests, substantial documentation, build tooling, recent commit and pull-request activity, and no deprecation or dangerous workflow findings. The main reservations are that the package is young with only three releases, all recent repository commits come from one contributor, and the repository lacks an explicit security policy and top-level GitHub Actions token permissions; these are meaningful hygiene and continuity concerns, but organizational ownership and recent activity reduce the abandonment risk.
76%
Total Score
90
100
89
80
The package is only 79 days old and has three releases, with a median release interval of about 79 days; this is limited evidence of long-term stability, though releases have continued through the assessment period.
All nine recent commits came from one contributor, giving the repository a concentrated bus factor. Organizational ownership provides some handoff capacity, but no second active contributor is shown in this signal.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected; the missing automated security coverage is a modest hygiene gap.
No repository security policy was found. This reduces transparency around vulnerability reporting and response expectations, although it does not by itself indicate abandonment.
All 10 workflows lack top-level token permission declarations. Although none declares top-level write permissions, explicitly constraining workflow tokens would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.20.0 | — | — |
symfony/asset Version ^5.4.33 || ^6.4.1 || ^7.0.1 || ^8.0.0 | — | — |
symfony/config Version ^5.4.31 || ^6.4.0 || ^7.0.0 || ^8.0.0 | — | — |
symfony/routing Version ^5.4.33 || ^6.4.1 || ^7.0.1 || ^8.0.0 | — | — |
symfony/var-dumper Version ^5.4.29 || ^6.4.0 || ^7.0.0 || ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.