The project has a clear MIT license, tests, documentation, and a recent release, with no install-time scripts. Its package-wide registry deprecation makes this release unsuitable as a new dependency despite the active repository and stable version.
20%
Total Score
75
100
81
83
The registry marks the entire package as abandoned, not just this release, and provides symfonycorp/connect as a replacement. This is a severe adoption risk even though recent releases exist.
The repository recorded no commits and no active maintainers in the last 3 months. The recent release and push show some activity, but the current development pause limits maintenance confidence.
Composer build tooling is present, but no security-scanning tooling was detected. This is a hygiene gap, partly offset by the repository's security policy.
The single workflow was fully analyzed with no audit findings and no dangerous triggers or untrusted checkouts. All 5 action references are unpinned, which is a supply-chain hygiene weakness, while the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/routing Version ^5.4|^6.4|^7.3|^8.0 | — | — |
symfony/http-client Version ^5.4|^6.4|^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.