Its release notes, repository tests, and organization ownership add useful context. Recent work is concentrated in one contributor, and the only workflow action is unpinned, leaving modest maintenance and build-hygiene concerns.
78%
Total Score
75
100
86
88
All three commits in the last three months came from one contributor. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
Composer build tooling is present, but no repository security-scanning tool was detected; this is a modest transparency and maintenance gap rather than a severe risk.
Although the package is below a stable major version, v0.14.0 is not a prerelease and recent releases contain no prerelease versions, so stability is reasonable with some API-change risk.
The sole workflow uses a pull_request_target trigger without untrusted checkout or script injection, and has no audit findings. However, its one action reference is unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/clock Version ^7.3|^8.0 | — | — |
symfony/ai-platform Version ^0.14 | — | — |
symfony/rate-limiter Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.