Clear licensing, repository tests, and release notes for this version improve transparency. One workflow action is unpinned, and all three recent commits came from one contributor.
78%
Total Score
83
92
75
All three recent commits came from one contributor, concentrating maintenance knowledge and creating a meaningful continuity risk. Symfony organization backing partly offsets the risk but does not remove it.
v0.14.0 is not a stable major release, so API stability may be lower than for a 1.x package; it is nevertheless not a prerelease and recent releases have no prerelease share.
The single workflow was fully analyzed with no untrusted checkout, script injection, or auditor findings; its pull_request_target trigger is harmless without a sink. However, its one action reference is unpinned, which is a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.3|^8.0 | — | — |
symfony/ai-agent Version ^0.14 | — | — |
symfony/filesystem Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.