The MIT license, repository tests, release notes, and security policy improve transparency. Its young 0.x maturity and minimal workflow hygiene leave less evidence for long-term resilience.
68%
Total Score
83
88
75
All 3 recent commits came from one contributor, giving the project a concentrated maintenance base. Symfony organization backing partly compensates by providing a potential handoff path, but recent activity still lacks contributor diversity.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a maintenance and hygiene gap, not evidence that the release is unsafe.
Version 0.14.0 is not a prerelease, but the package remains below a stable major version. That signals some API maturity risk for dependents.
The sole workflow uses a pull_request_target trigger without an untrusted checkout or script injection, and the audit completed cleanly. However, its one action reference is unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-chat Version ^0.14 | — | — |
symfony/serializer Version ^7.3|^8.0 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.