The package is small and focused, with clear documentation, repository tests, a changelog, and an MIT license. Its narrow scope and organization ownership provide useful context for the limited activity shown.
78%
Total Score
67
88
88
All three recent commits came from one contributor. The Symfony organization owns the repository, which provides some handoff capacity, but recent contribution concentration remains a maintenance risk.
Three commits in the last three months show recent activity, though the volume is modest for the period.
Composer build tooling is present, but no repository security-scanning tool was detected; this is a modest transparency and hygiene gap rather than a severe risk.
The current release is not a stable major version, but it is not marked as a prerelease and recent releases contain no prerelease versions; this is a maturity caveat rather than an abandonment concern.
The sole workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection sinks. However, its one action reference is unpinned, creating a minor reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-platform Version ^0.14 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
symfony/ai-generic-platform Version ^0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.