description
38%
Total Score
unhealthy
Risky: no releases in over three years, an early 0.1 version, and a single maintainer.
The package has had no release in over three years, with all four releases clustered near its May 2023 launch and none in the last 12 months. This is strong evidence of abandonment risk.
Eight runtime dependencies, including several framework and ORM components, create a meaningful compatibility and maintenance burden for a small 0.1 package.
Only one account has registry publish access, leaving little visible publishing redundancy and increasing bus-factor risk. Registry access alone does not prove maintenance activity, so this is supporting rather than decisive evidence.
Version 0.1.2 is not a stable major release, so the package has limited maturity evidence and may carry compatibility risk. It is not marked as a prerelease, which provides only minor compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cycle/orm Version ^2.3 | — | — |
symfony/config Version ^6.2 | — | — |
cycle/annotated Version ^3.3 | — | — |
symfony/http-kernel Version ^6.2 | — | — |
doctrine/collections Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.