Frequent releases, stable versioning, and Composer-based tooling provide useful support. The small project footprint and limited workflow hardening leave more maintenance uncertainty than its release history suggests; pin 2.0.83 if adopting it.
58%
Total Score
75
93
67
The repository recorded zero commits and zero active maintainers in the last 3 months. That is a meaningful maintenance concern, despite the package's otherwise frequent release history.
The repository name does not match the package name, and its README does not mention the package. This raises uncertainty about whether the linked source repository directly belongs to this release.
The repository has no security policy file. This is a transparency and vulnerability-reporting gap, though GitGuardian scanning provides some compensating security tooling.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or auditor findings, but all 5 action references are unpinned. The absence of a top-level permissions block is acceptable here because no write-wide permissions were observed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
symfony/config Version ^7.4||^8.0 | — | — |
survos/core-bundle Version ^2.0 | — | — |
symfony/http-kernel Version ^7.4||^8.0 | — | — |
knplabs/knp-menu-bundle Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.