Recent commits and releases show ongoing maintenance, with tests, release notes, and a security policy supporting transparency. The workflow audit found no active findings, though its single action is unpinned and recent commits are concentrated in two contributors.
82%
Total Score
83
100
94
100
Two contributors are active, but one accounts for 80% of recent commits, leaving some concentration risk. Symfony organization backing provides partial resilience.
Composer build tooling is present, but no security-scanning tool was detected, which is a minor transparency gap rather than evidence of unsafe code.
The single workflow was fully analyzed with no audit findings, no untrusted checkout, and no script injection. Its one action is unpinned and the workflow lacks a top-level permissions block, creating minor reproducibility and permission-hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.3|^8.0 | — | — |
symfony/clock Version ^7.3|^8.0 | — | — |
symfony/serializer Version ^7.3|^8.0 | — | — |
symfony/ai-platform Version ^0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.