Documentation, tests, and a clear MIT license make adoption easier. The small project has no security policy, and its workflow dependencies are all unpinned.
78%
Total Score
67
100
94
75
The repository is owned by an individual user rather than an organization. That is consistent with the two-person maintainer base but provides less visible maintenance redundancy.
Two contributors were active recently, but the top contributor made 75% of the commits. That concentration leaves some maintainer-continuity risk for a user-owned project.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces automated supply-chain visibility without making the package unfit by itself.
The repository has no security policy. For a server-side library, this is a transparency gap because it gives users no documented path for reporting vulnerabilities.
The single workflow was fully analyzed and uses read-only permissions, with no dangerous audit findings. However, all 3 action references are unpinned, leaving avoidable action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ~2.7 | >=3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.