Package Health

symfony/ai-demo

The package is clearly documented, licensed, and covered by a maintained organization-backed project. Its small contributor base and absent automated security scanning leave modest resilience gaps.

Latest v0.14.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dependency profilecaution

The demo declares 46 runtime dependencies, including many Symfony AI and infrastructure components, which increases maintenance and transitive-dependency exposure for adopters.

Repo bus factorcaution

Two contributors are active, but one accounts for about two-thirds of recent commits, leaving some contributor-concentration risk; organization backing partly offsets it.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tools were detected, leaving a modest transparency and monitoring gap.

Version stabilitycaution

This is a non-prerelease v0.14.0 release, although the package remains below a stable major version, so some API change risk remains.

Workflow auditcaution

The only workflow uses pull_request_target without an untrusted checkout or script-injection sink, and it has no top-level write permissions. Its sole action reference is unpinned, a minor reproducibility concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.22
—
—
nyholm/psr7
Version ^1.8
—
—
symfony/uid
Version ^8.1
—
—
symfony/flex
Version ^2.10
—
—
symfony/form
Version ^8.1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform