Its focused artifact includes tests, a matching repository, and a clear Apache-2.0 license. The organization owner offers some continuity, but there is no demonstrated maintenance history yet.
58%
Total Score
75
100
88
88
The package is brand new: it has one release and was first published 0 days ago, so there is no release track record to establish maintenance reliability.
The repository records zero commits and zero active maintainers over the last three months. Because the project is 0 days old, this shows limited demonstrated maintenance rather than established abandonment, but it still reduces confidence.
Composer is used as the build tool, but no security scanning tooling is reported. This is a modest repository-hygiene gap rather than a standalone dependency risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/workflow Version 7.4.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.