Regular releases and a clear README make adoption easier. Organization backing helps offset the narrow recent contributor base, while workflow references are not pinned.
68%
Total Score
67
94
67
One contributor made 100% of the six recent commits. The organization-owned project provides some handoff capacity, but recent maintenance remains highly concentrated.
Six commits were made in the last 3 months, showing current activity. However, all activity came from one active maintainer, limiting resilience if that person stops contributing.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and assurance gap rather than evidence of abandonment.
The repository has no security policy. For a maintained library this reduces clarity about vulnerability reporting and response expectations.
All three workflows were analyzed successfully with no high-confidence audit findings or untrusted checkouts. However, all 9 action references are unpinned, leaving build inputs less reproducible; the lack of top-level permissions is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 || ^4.0 | — | — |
doctrine/orm Version ^2.6,>=2.6.3 || ^3.0 | — | — |
2lenet/crudit-bundle Version ^1.12 | — | — |
doctrine/persistence Version ^2.0 || ^3.0 || ^4.0 | — | — |
doctrine/doctrine-bundle Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.