The package includes tests in its source repository, release notes for this version, and a clear MIT license. Its workflow has one unpinned action, but no dangerous checkout, injection, or high-severity findings were reported.
86%
Total Score
100
100
88
100
Composer build tooling is present, but no security scanning tool was detected. The missing scan is a modest transparency gap, not evidence of unsafe behavior by itself.
v0.13.0 is not a prerelease, although the package remains below a stable major version. The absence of recent prereleases is a positive, while the 0.x status warrants only limited caution.
The single workflow uses a pull_request_target trigger and one unpinned action, creating a minor workflow-hygiene concern. However, the audit found no untrusted checkout, script injection, dangerous permissions, or severity-rated findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version ^1.47 | — | — |
symfony/ai-platform Version ^0.13 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
symfony/ai-gemini-platform Version ^0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.