The package has a matching repository, a clear MIT license, a useful README, and tests in the source project. Its release and commit activity is now quiet, and workflow dependencies are unpinned.
60%
Total Score
50
88
50
The package has 12 releases since January 2016, but none in the last 12 months; the latest release was about 2 years and 3 months ago. This indicates a meaningful maintenance slowdown for a framework bundle.
There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last year, this is evidence of limited current maintenance.
The repository uses Composer, but no security scanning tool was detected. This is a modest transparency and maintenance-process gap, not evidence that the package is unsafe.
The repository has no security policy. For a reusable Symfony bundle this leaves vulnerability reporting expectations unclear, creating a minor transparency concern.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 3 action references are unpinned. That weakens build reproducibility and supply-chain hygiene without making the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4||^6.0 | — | — |
symfony/finder Version ^5.4||^6.0 | — | — |
symfony/http-kernel Version ^5.4||^6.0 | — | — |
symfony/framework-bundle Version ^5.4||^6.0 | — | — |
symfony/dependency-injection Version ^5.4||^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.