Tests, an MIT license, and organization backing provide a solid starting point. The project is too new to demonstrate sustained maintenance, and its workflows use nine unpinned actions.
62%
Total Score
75
100
75
67
The package includes tests, the repository includes tests, and this version has a GitHub release. The missing README and changelog are transparency gaps, though the tests and release record partly compensate.
The package is 0 days old with only one release, so it has not yet demonstrated a sustained release history. Its organization-backed repository and current release provide some context, but not evidence of maturity.
There were zero commits and zero active maintainers during the last three months. Because the package was first released today, this mainly leaves maintenance capacity unproven rather than showing a long-term collapse.
Composer build tooling is present, but no security-scanning tool was detected. The build setup is appropriate, while security coverage remains limited.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, not evidence of an unsafe implementation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/webhook Version * | — | — |
symfony/http-client Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.