Symfony bundle Bot API for Max Messenger
62%
Total Score
caution
A young package with no commits in the last three months has limited maintenance evidence.
The package is only 109 days old and has had two releases, both published within about 35 minutes, so its longer-term maintenance pattern is unproven.
There were no commits and no active maintainers in the last three months. Because the project is young, this is limited evidence rather than proof of abandonment, but it weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That is a hygiene gap for a package handling webhook and access-token configuration.
The repository has no security policy. This reduces transparency about how vulnerabilities should be reported, although it is not by itself evidence of an unsafe release.
Version 0.0.2 is not a stable major release, which indicates an immature API and a higher likelihood of breaking changes for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.0 || ^7.0 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 | — | — |
symfony/http-foundation Version ^6.0 || ^7.0 | — | — |
symfony/framework-bundle Version ^6.0 || ^7.0 | — | — |
symfony/dependency-injection Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.