Documentation and packaging are solid, with tests and release notes maintained in the source repository. The project is too new to show an established maintenance track record, and workflow dependency pinning remains a practical weakness.
73%
Total Score
75
100
88
75
This is a brand-new package with four releases published within roughly one hour, so it has not yet demonstrated a sustained release or maintenance history.
No commits or active maintainers were observed in the last three months, but the package itself is only hours old and the repository was just pushed, so this is limited evidence rather than abandonment.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest verification gap for a newly published package.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The single workflow uses read-only permissions and has no detected dangerous sinks or audit findings, but all four referenced actions are unpinned, weakening build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/web-link Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.