The bundle has a clear README, tests, changelog, license, and Psalm checks. Its automated actions are not pinned and the repository lacks a security policy; pin this version if its behavior fits your application.
61%
Total Score
50
94
83
The repository is owned by a user account rather than an organization, so the single registry maintainer does not benefit from visible organizational backing; this modestly limits maintenance redundancy.
The package has five releases since August 2021, but none in the last 12 months; the latest release was in December 2023, indicating materially slowed maintenance.
There were zero commits and zero active maintainers in the three months measured, consistent with maintenance having stopped after December 2023 and increasing abandonment risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented for a dependency intended for application integration.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.3 || ^7.0 | — | — |
league/commonmark Version ^2.2.0 | — | — |
symfony/http-kernel Version ^6.3 || ^7.0 | — | — |
symfony/framework-bundle Version ^6.3 || ^7.0 | — | — |
symfony/dependency-injection Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.