Tests, clear licensing, and organization backing provide useful maintenance and transparency evidence. The project has not released in 12 months, has had no commits in 3 months, and lacks repository security safeguards.
62%
Total Score
75
100
88
75
The package has 8 releases over about 5 years, but none in the last 12 months. That indicates a meaningful slowdown in delivery, despite a previously regular median release interval of about 33 days.
There were zero commits and zero active maintainers in the last 3 months. This is strong evidence of currently paused maintenance and increases the risk that issues or compatibility changes will be missed.
The repository uses Make and Composer, but no security scanning tools were detected. That is a moderate transparency and maintenance-process gap for a package intended for application integration.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
The single workflow was fully analyzed with no audit findings or dangerous triggers, but 2 of its 3 action references are unpinned. That leaves avoidable build-integrity risk, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.1|^6.4 | — | — |
symfony/process Version ^7.1|^6.4 | — | — |
symfony/security-bundle Version ^7.1|^6.4 | — | — |
symfony/event-dispatcher Version ^7.1|^6.4 | — | — |
symfony/framework-bundle Version ^7.1|^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.