The package is well documented and tested in its source, with a clear MIT license and no install-time scripts. Symfony organization backing and a security policy help offset the young, experimental project and concentrated recent contribution.
72%
Total Score
67
100
86
100
All seven recent commits came from one contributor. Symfony organization backing provides some handoff capacity, but no second active contributor is shown in this signal.
Seven commits in the last three months indicate ongoing work, but only one maintainer was active during that period, limiting demonstrated maintenance capacity.
The repository uses Composer build tooling, but no security scanning tools were detected; the missing scanning is a modest hygiene gap rather than evidence of abandonment.
Version v3.5.1 is a stable, non-prerelease release, although the package documentation identifies the component as experimental and subject to substantial change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.4|^8.0 | — | — |
symfony/clock Version ^7.4|^8.0 | — | — |
symfony/twig-bundle Version ^7.4|^8.0 | — | — |
symfony/framework-bundle Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.