The README is detailed and the package is clearly linked to its repository. Its broad dependency set and lack of repository security controls add maintenance overhead for a security-sensitive bundle.
65%
Total Score
50
88
88
The package declares 28 runtime dependencies, including several framework and Symfony/Sylius components. That broad dependency surface increases upgrade and compatibility maintenance burden.
This is the package's first release, published less than one hour ago, so there is no release track record or sustained cadence to assess. The repository's matching source and substantial file tree provide some compensating transparency, but not evidence of long-term maintenance.
Composer build tooling is present, but no security scanning tools are configured. For an identity and access management bundle, that is a meaningful repository hygiene gap.
The repository has no security policy. That reduces transparency about how consumers should report vulnerabilities in a security-sensitive package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.0 || ^8.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^7.0 || ^8.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/clock Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.