The package includes tests, a current release note, and no install-time scripts. Unpinned workflow actions, no security policy or scanning, and no recent commits leave maintenance and build hygiene weaker than its organization backing suggests.
68%
Total Score
75
81
75
The package is about 2 years and 7 months old with 4 releases, but only 1 release in the last 12 months and a median interval of about 364 days indicate a slow maintenance cadence.
The repository had 0 commits and 0 active maintainers in the last 3 months, which is a concrete sign of limited recent development activity despite the recent release.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not determine the health of a small, organization-backed package.
Composer is used for builds, but no security scanning tools are configured, leaving a maintenance and vulnerability-detection gap.
The repository has no security policy, so there is no documented route for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.4.2|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.