The repository is small and has limited operational security coverage. Its README, tests, release notes, and license make adoption clearer. The single-maintainer project has not committed in 10 months, and its workflow uses three unpinned actions.
58%
Total Score
50
83
75
Only one registry maintainer is listed, which creates a thin publishing and support base. The linked repository is owned by the same individual, so there is no visible broader maintainer capacity to offset that risk.
This is a young package with one release, published 10 months ago, and no demonstrated release cadence yet. That limits evidence of sustained maintenance but is not abandonment by itself.
The repository recorded zero commits and zero active maintainers during the last 3 months; its last push was about 10 months ago. For a package this new, the inactivity creates a meaningful maintenance concern.
The project uses Composer but reports no security-scanning tooling. Build tooling is present, while the missing scanning layer modestly reduces supply-chain and vulnerability visibility.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.0|^8.0 | — | — |
symfony/http-client Version ^7.0|^8.0 | — | — |
symfony/http-kernel Version ^7.0|^8.0 | — | — |
symfony/dependency-injection Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.