Usable with caveats: the package is clearly documented, licensed, actively publishing, and backed by a matching repository, but it is brand new with no established commit history and has limited security governance. Review the binary-download workflow before adopting it in production.
62%
Total Score
50
100
83
75
Only one registry account has publishing access. The repository is user-owned rather than organization-owned, so the single-person publishing base is a real continuity risk.
The repository owner is a user account rather than an organization, so there is no organizational backing shown. The registry namespace and repository identity are still consistent with the project.
The package is extremely new, only about 24 hours old, despite having 12 releases and 11 releases in the last year. That rapid initial publishing does not yet demonstrate long-term maintenance.
The repository reports zero commits and zero active maintainers during the last three months. Because the project is less than a day old, this may reflect limited history rather than abandonment, but it provides no established maintenance record.
The repository has zero stars, forks, and watchers. This is expected for a newly published project and is supporting evidence only, but it provides no external adoption signal yet.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.