Clear documentation, licensing, and release notes support straightforward adoption. The package is still early-stage and recent work is concentrated in one contributor, while the workflow has an unpinned action. Pin this version only if its pre-1.0 API fits your project.
79%
Total Score
83
100
88
88
All six recent commits came from one contributor, leaving maintenance dependent on a single active individual. Organization backing partly compensates, but the concentration remains a resilience concern.
Composer build tooling is present, but no repository security-scanning tool was detected. The missing scanner is a hygiene gap rather than evidence of unsafe behavior.
Version 0.14.0 is not a stable-major release, so its API may still change; however, it is not a prerelease and recent releases have not been marked prerelease.
The sole workflow uses pull_request_target without an untrusted checkout or script injection, and the audit found no security findings. However, its one action is unpinned, reducing build reproducibility; the absence of a top-level permissions block is acceptable here because no broad write permission is granted.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.3|^8.0 | — | — |
symfony/ai-store Version ^0.14 | — | — |
symfony/ai-platform Version ^0.14 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.