Usable with caveats: it is actively released, documented, licensed, and backed by a repository with tests and safe workflow patterns. The release is explicitly experimental, and all recent commits come from one contributor with limited security-policy and workflow-permission hygiene.
68%
Total Score
75
92
67
One contributor made all 76 commits in the last 3 months, creating a meaningful continuity risk for a user-owned project without organizational backing.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, but not by itself evidence that the package is unsafe.
One workflow lacks top-level permissions and another declares write permissions, so the repository's GitHub Actions privilege boundaries are less explicit and conservative than ideal.
Version 2.0.0-rc1 is explicitly a pre-release rewrite with expected breaking changes, so production users face avoidable compatibility risk despite the package having a stable-major release profile overall.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4|^7.4|^8.1 | — | — |
symfony/asset Version ^6.4|^7.4|^8.1 | — | — |
symfony/process Version ^6.4|^7.4|^8.1 | — | — |
league/flysystem Version ^3.35 | — | — |
symfony/web-link Version ^6.4|^7.4|^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.