Clear documentation, tests, licensing, and a security policy provide useful project transparency. Releases are recent and the repository is active, though reported security scanning is absent.
72%
Total Score
88
100
94
88
All four recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is evidenced, leaving a real maintenance concentration risk.
Composer build tooling is present, but no security-scanning tool is reported, leaving a project hygiene gap for a library handling API credentials and integrations.
All three workflows were analyzed without failed files or high-confidence findings, and no untrusted checkout or script-injection path was found. However, all five action references are unpinned and one workflow grants top-level write access, creating a moderate CI reproducibility and token-scope concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.