The repository has only one active contributor, and it lacks a security policy. MIT licensing, pinned workflow actions, and release notes improve transparency.
78%
Total Score
88
100
88
83
All two recent commits came from one contributor, so maintenance is concentrated despite the repository belonging to an organization.
The repository name does not match the package name, and no README package mention was collected, creating some uncertainty about the package-to-repository linkage; the bundle-style repository name is consistent with a sub-package layout.
The repository has zero stars and forks and two watchers, offering little community adoption evidence; popularity is supporting evidence only and does not outweigh the recent releases and organization backing.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
guzzlehttp/guzzle Version ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.