A single contributor made all four recent commits, and the only workflow uses an unpinned action. Regular releases, a matching repository, tests, and Symfony organization backing reduce abandonment concerns.
78%
Total Score
67
100
93
100
One contributor made all four commits in the last three months, creating a concentrated recent bus factor. The organization-owned project provides some handoff capacity, so this is a caution rather than a severe risk.
There were four commits in the last three months, so activity has not stopped. However, all recent activity came from one active maintainer, which modestly increases continuity risk.
The repository uses Composer build tooling, but no security scanning tools were detected. That is a transparency and hygiene gap, though it is partly offset by the repository's organizational backing and security policy.
The single workflow is fully analyzed and has no detected dangerous sinks or audit findings, but its one action use is unpinned. The pull_request_target trigger is ordinary on its own, while the missing top-level permissions block is not a concern by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/clock Version ^7.3|^8.0 | — | — |
symfony/ai-platform Version ^0.13 | — | — |
symfony/rate-limiter Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.