Documentation and packaging are in good shape, with tests, a changelog, a license, and no install-time scripts. Organization backing and regular releases help offset the narrow recent contributor base; pin the workflow action before relying on it for releases.
72%
Total Score
67
86
100
One contributor made all seven recent commits. Organization ownership provides some handoff capacity, but no second recent contributor is shown to share the load.
Seven commits were made in the last three months, but all activity came from one active maintainer, leaving limited recent maintenance capacity.
The project uses Composer, but no security-scanning tools were detected, leaving a modest repository-hygiene gap.
This is a non-prerelease 0.13.0 release, but the package has not reached a stable major version, so compatibility expectations remain more limited.
The single workflow uses a pull_request_target trigger but has no untrusted checkout or script-injection findings. Its sole action reference is unpinned, which is a supply-chain hygiene weakness even though the audit found no direct vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-platform Version ^0.13 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
symfony/ai-meta-platform Version ^0.13 | — | — |
symfony/ai-generic-platform Version ^0.13 | — | — |
symfony/ai-open-ai-platform Version ^0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.