Regular releases, repository tests, and release notes provide useful confidence. The main limitation is that all seven recent commits came from one contributor, despite Symfony organization backing.
72%
Total Score
83
86
100
One contributor made all seven recent commits, creating a real maintenance concentration risk; Symfony organization backing partly compensates for that risk.
The repository has only 2 stars and no forks or watchers, indicating limited external adoption; this is supporting evidence rather than a decisive health problem.
This release is not prerelease, but the package remains on a pre-1.0 major version, so API stability may be less mature.
The single workflow was fully analyzed with no audit findings or untrusted checkout and script-injection sinks. Its only uses reference is unpinned, which is a minor reproducibility concern, while the pull_request_target trigger is not risky on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.3|^8.0 | — | — |
symfony/ai-store Version ^0.13 | — | — |
symfony/ai-platform Version ^0.13 | — | — |
probots-io/pinecone-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.