Usable with caveats: this is a very new package with only two releases over one day and no recorded repository activity yet. It has clear documentation, matching organization-backed source, and no deprecation or install scripts, but its maintenance and testing record are still unproven.
62%
Total Score
67
100
88
50
One registry publishing account is listed, which is a limited direct maintainer base. The linked repository is organization-owned, providing some backing that offsets the narrow registry account list.
The package is only 1 day old and has just 2 releases, so there is not enough history to demonstrate sustained maintenance or maturity.
No commits or active maintainers were recorded during the last 3 months, but the repository is only 1 day old and was pushed about 6 minutes before collection, so this is weak evidence of risk rather than proof of abandonment.
The repository uses Composer for its build, which fits the package ecosystem, but it has no security scanning tools. The missing scanning is a modest transparency gap for a new dependency.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented. This lowers transparency but is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/messenger Version ^7.0 | — | — |
symfony/serializer Version ^7.0 | — | — |
symfony/amqp-messenger Version ^7.0 | — | — |
wexample/symfony-helpers Version >=8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.