It has clear licensing, tests, release notes, and a steady release cadence. The small 0.x package and unpinned workflow action leave modest maturity and build-reproducibility concerns.
72%
Total Score
67
100
88
100
One contributor made all four recent commits, creating concentration risk; Symfony organization backing provides some ability to hand off maintenance but does not remove the current concentration.
Four commits were made in the last three months, showing ongoing work, though all activity came from one maintainer.
Composer build tooling is present, but no repository security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The release is not a prerelease, but it remains on an unstable 0.x major version, so compatibility maturity is limited.
The only workflow uses a pull_request_target trigger without an untrusted checkout or script injection, and has no high-confidence findings. However, its sole action reference is unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/clock Version ^7.3|^8.0 | — | — |
symfony/ai-agent Version ^0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.