The package includes a focused README, release notes, repository tests, and a clear MIT license. Its small contributor base and unpinned workflow action leave some maintenance and build-integrity risk.
78%
Total Score
83
94
100
All 4 recent commits came from one contributor, giving the project a concentrated maintenance base. Symfony organization backing partly reduces handoff risk, but does not remove it.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of unsafe code.
The single workflow was fully analyzed with no audit findings or untrusted checkout and has no top-level write permissions. However, its only action reference is unpinned, which weakens reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
symfony/ai-agent Version ^0.13 | — | — |
php-http/discovery Version ^1.19 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
mrmysql/youtube-transcript Version ^0.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.