Package Health

symfony/ai-platform

The project has strong documentation, tests, release notes, and broad recent contributor activity. Its experimental 0.x status and a workflow without explicit token permissions add caution for production use.

Latest v0.13.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

One analyzed workflow uses pull_request_target, which warrants review because that trigger can expose privileged workflow behavior to pull requests, although no untrusted checkout or script injection was detected.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.

Token permissionscaution

The sole workflow has no top-level token permissions declaration. It declares no write permissions, but the absence of an explicit restrictive policy leaves workflow privileges less transparent.

Version stabilitycaution

The current release is a non-prerelease 0.13.0, but the major version is still below 1.0 and the README explicitly calls the component experimental, so backward compatibility is not promised.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christopher Hertel
Oskar Stark
Symfony Community

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
symfony/uid
Version ^7.3|^8.0
symfony/clock
Version ^7.3|^8.0
symfony/type-info
Version ^7.3|^8.0
symfony/serializer
Version ^7.3|^8.0

Weekly Downloads

Info

Last Published
21 days ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform