This release presents a well-structured and apparently maintained package: it includes a README, tests, changelog, license file, explicit stable versioning, no install-time scripts, a matching repository, and recent activity from two contributors under an organization-owned project. The main reservation is that the package is only 3 days old with just 3 releases, so long-term stability and maintenance are unproven; repository security hygiene is also incomplete because no security policy or security scanning is reported and the CI workflow does not declare top-level token permissions. It is reasonable to evaluate as a dependency, but production adoption should be paired with version pinning and continued maintenance monitoring.
78%
Total Score
100
100
83
80
The package is only 3 days old and has 3 releases, so it has limited evidence of long-term maintenance and compatibility stability despite a frequent initial release cadence.
The repository has 0 stars, forks, and watchers, so there is no community adoption evidence yet; this is understandable for a 3-day-old package but still leaves external validation unestablished.
Composer build tooling is present, but no security scanning tools are reported, leaving a security-process gap that is relevant to dependency consumers.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
The single CI workflow lacks top-level token permissions declarations. No write permissions are reported, but explicitly restricting permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/process Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/filesystem Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.