Usable with caveats: this is a well-structured, licensed package from an organization-backed repository, but it was released today and has no demonstrated release or commit history yet. Reassess after it establishes a track record.
65%
Total Score
75
100
83
90
Only one release exists and the package is 0 days old, so there is no established release cadence or evidence of sustained maintenance yet.
The repository has zero commits and zero active maintainers in the last 3 months; because the project is newly released, this is mainly an absence of demonstrated history rather than proof of abandonment.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption; the organization backing and substantive package contents partly compensate for this weak popularity signal.
Composer is used as a build tool, but no security scanning tool was detected. The build setup is positive, while the missing scanning coverage is a modest transparency gap.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for a package that includes extensive provisioning scripts.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 || ^7.0 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
symfony/process Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.