The bundle is licensed, tested, documented, and backed by an organization-owned project. Unpinned workflow actions and the missing security policy add smaller maintenance concerns.
58%
Total Score
75
83
50
The package has 17 releases over roughly 10 years but none in the last 12 months; its latest release was on May 28, 2024, indicating a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, which supports the broader evidence of stalled maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap but not evidence that the package is unsafe.
Version 0.11.2 is not on a stable major version, although it is not marked as a prerelease and recent prerelease usage is zero.
All 6 of 6 analyzed action references are unpinned, reducing build reproducibility. The audit found no untrusted checkouts, script injection, elevated top-level writes, or other reported findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/messenger Version ^5.4 || ^6.4 || ^7.0 | — | — |
prooph/event-store Version ^7.9.0 | — | — |
symfony/http-kernel Version ^5.4.39 || ^6.4 || ^7.0 | — | — |
symfony/framework-bundle Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.