A single contributor handled all four recent commits, and the repository has no security scanning. The license, tests, release notes, regular publishing, and Symfony organization backing provide useful transparency.
78%
Total Score
67
88
100
One contributor made all four commits in the last three months, creating a narrow recent maintenance base. Symfony organization backing partly offsets the handoff risk but does not remove the concentration.
The repository recorded four commits in the last three months, showing ongoing work, but the activity is modest for a package with regular releases.
Composer build tooling is present, but no security scanning tools were detected. That is a meaningful transparency and maintenance gap, though it is not evidence of a specific defect.
Version v0.13.0 is not a stable-major release, so its API may still change. It is nevertheless a normal release rather than a prerelease, which limits the concern.
The only workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection paths. Its single action is unpinned, which is a minor reproducibility and workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-platform Version ^0.13 | — | — |
codewithkyrian/transformers Version ^0.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.