The source includes tests, a clear license, and a recent release, but no commits in the last three months. Its workflows use unpinned actions and inherit secrets, adding avoidable maintenance risk.
38%
Total Score
75
79
75
Packagist marks the entire package as abandoned and names unleash/symfony-client-bundle as its replacement. This is a direct maintenance concern for anyone starting a new dependency.
The repository recorded zero commits and zero active maintainers in the last three months. That inactivity is concerning despite the recent release history.
The repository name does not match the package name and its README does not mention the package. Although subpackages can use monorepos, both gaps make package ownership less transparent.
No security policy was found in the repository. This is a modest transparency gap, though the reported security scanning provides partial compensation.
All 17 analyzed action references are unpinned, and the audit found a high-confidence medium-severity secrets-inherit issue in a pull_request_target workflow. No untrusted checkout or script injection was found, which limits the impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.0 | — | — |
symfony/cache Version ^5.0 | ^6.0 | ^7.0 | ^8.0 | — | — |
unleash/client Version ^2.4 | — | — |
symfony/http-client Version ^5.0 | ^6.0 | ^7.0 | ^8.0 | — | — |
symfony/event-dispatcher Version ^5.0 | ^6.0 | ^7.0 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.