Clear licensing, repository tests, release notes, and organizational backing improve confidence in the project. The GitHub workflow uses an unpinned action, and recent commits are concentrated in one contributor.
78%
Total Score
75
100
88
100
One contributor made all five commits in the last three months, which creates concentration risk; Symfony organizational ownership provides some capacity to hand maintenance off, but no second recent contributor is shown.
Five commits in the last three months show recent activity, but all came from one active maintainer, leaving limited recent redundancy.
Composer build tooling is present, but no security-scanning tool was detected. The repository's separate security policy partly offsets this tooling gap.
This is a non-prerelease release, although the package remains below major version 1, so its API maturity may still be evolving.
The sole workflow is fully analyzed and has no detected injection or other audit findings, but its one action reference is unpinned. The pull_request_target trigger is ordinary here because no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-platform Version ^0.13 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.