The package is MIT-licensed, has no install-time scripts, and its repository is not archived. Documentation is thin, and the small project shows limited security and maintenance evidence.
56%
Total Score
0
67
75
This is the package's only release, published over five years ago, with no releases in the last 12 months. That makes ongoing compatibility and maintenance uncertain.
The repository recorded no commits and no active maintainers in the last three months. Combined with the single registry release, this points to weak current maintenance capacity.
The artifact has no README, which limits consumer guidance for a Symfony integration package. The exact release does have GitHub release notes, partly compensating for the absent changelog; missing tests and changelog files are normal packaging practice.
Composer is used for the build, but no security scanning tools were detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version >=5.3 | — | — |
symfony/http-kernel Version >=5.3 | — | — |
symfony/http-foundation Version >=5.3 | — | — |
symfony/event-dispatcher Version >=5.3 | — | — |
symfony/dependency-injection Version >=5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.