Healthy and reasonable to depend on. It has a stable release history, a matching repository with tests, recent repository activity, clear licensing, and no deprecation or risky workflow findings. The small maintainer base and limited security governance are the main caveats.
78%
Total Score
63
100
94
80
Only one account has registry publishing access, creating a limited publishing continuity margin. The linked repository is maintained under the same user-owned project, which provides some compensating ownership context.
The repository recorded no commits and no active maintainers during the last three months, which is a maintenance warning. However, the recent release history and repository push provide some compensating evidence rather than indicating abandonment.
There are only two open issues and no recent issue or pull-request activity. This is not itself a severe concern, but it provides limited evidence of active user or maintainer interaction.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing security automation is a governance gap, though it does not by itself make the package unfit to use.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented. This lowers transparency but is not a standalone dependency blocker for this small library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.