It has a clear Apache-2.0 license, included tests, and organization backing. The limited security tooling and absent security policy leave less assurance than a mature dependency would provide.
64%
Total Score
75
100
88
83
This is the package's first release, published today, with only one release recorded and no release cadence established. That makes maintenance and compatibility maturity unproven, but does not by itself indicate abandonment.
The repository has zero commits and zero active maintainers in the last three months. Because the repository was created today, this is mainly a lack of established maintenance evidence rather than proof that activity has collapsed.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, although the package's first-day age limits how strongly this absence should be weighted.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version 7.4.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.