The package includes tests, documentation, a changelog, and a matching source repository backed by an organization. Its workflow uses read-only permissions but leaves all three actions unpinned, and the project has no security scanning or established activity yet.
68%
Total Score
75
100
79
75
This is the first release, published today, so there is no release cadence or track record to demonstrate sustained maintenance. That is expected for a new package but lowers maturity confidence.
There were no commits in the last three months and no active maintainers in that period. Because the package was only released today, this is mainly missing history rather than evidence of abandonment, but it limits confidence.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest repository hygiene gap, partly offset by the available tests and static configuration shown in the file tree.
The repository has no security policy. For a new package this is a transparency gap, though it is not severe enough to make the release unfit on its own.
Version 0.1.0 is an early, non-stable-major release, which signals that APIs and behavior may still change. It is not marked as a prerelease, so the concern is limited to maturity and compatibility expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.3 || ^8.0 | — | — |
symfony/process Version ^7.3 || ^8.0 | — | — |
symfony/http-kernel Version ^7.3 || ^8.0 | — | — |
symfony/dependency-injection Version ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.