The release has clear documentation, a matching MIT license, repository tests, and a published release note. Recent maintenance is quiet, and the workflow uses unpinned actions without a top-level permission policy, so pinning this version is prudent.
72%
Total Score
88
100
100
83
There were no commits and no active maintainers in the three months measured. A recent release and July push partly compensate, but this still indicates quiet current maintenance.
The repository has no security policy. For a bundle handling password-reset functionality, the absence of a documented vulnerability-reporting path is a real transparency gap.
The single workflow was fully analyzed with no untrusted checkout or script-injection trigger, and the low-confidence cache-poisoning finding is hygiene only. However, all three action references are unpinned, and the high-confidence template-injection finding warrants workflow review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/serializer Version ^5.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^5.1.5 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/http-foundation Version ^5.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/event-dispatcher Version ^5.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.