Usable with caveats: this young 0.x Symfony bundle has strong documentation, tests, licensing, and a non-archived repository. Its small user footprint, lack of a security policy, and roughly nine months since the latest release warrant review before production adoption.
68%
Total Score
75
100
78
80
Six releases in the past year show initial development activity, but the latest release was about nine months ago, which is a meaningful maintenance concern for a package whose README says it is still under active development.
There are no open issues or pull requests and no recent issue or merge activity. With no commit-activity signal provided, this is only a modest concern rather than evidence of abandonment.
The repository has only 1 star, 0 forks, and 0 watchers, indicating limited external adoption and review; this is supporting caution rather than proof of poor quality.
Composer build tooling is present, but no security scanning tool is configured, leaving a hygiene gap for a package intended to process XML and integrate with Symfony applications.
The repository has no security policy, reducing transparency about how users should report vulnerabilities or receive security guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.3|^7.4|^8.0 | — | — |
symfony/http-kernel Version ^7.3|^7.4|^8.0 | — | — |
symfony/serializer-pack Version ^1.3 | — | — |
symfony/dependency-injection Version ^7.3|^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.