Send PHP errors to Flare
88%
Total Score
88
100
94
80
Although three maintainers were active recently, one contributor made 21 of 23 commits (about 91%), creating a genuine concentration and continuity risk. The organization-owned repository provides some mitigation because maintenance can potentially be handed off within the organization.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it is not evidence of abandonment or an unsafe release by itself.
No repository security policy was found, leaving vulnerability-reporting guidance less explicit than ideal and creating a transparency gap.
All four workflows lack top-level token-permission declarations. No workflow declares top-level write access, which limits the concern, but explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^5.2|^6.0|^7.0|^8.0 | — | — |
psr/container Version ^2.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
symfony/console Version ^5.2|^6.0|^7.0|^8.0 | — | — |
symfony/process Version ^5.2|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.