The stable release line, tests, documentation, and organizational backing make the package easier to adopt. Maintenance has recently paused, while workflow references are not pinned and the repository has no security policy or scanning.
68%
Total Score
75
100
94
83
The repository recorded 0 commits and 0 active maintainers in the last 3 months, a concrete sign of recently paused development that lowers maintenance confidence.
There were no new or closed issues or pull requests in the last month, and 11 pull requests remain open; this suggests limited recent project interaction, although the release history partly compensates.
Composer build tooling is present, but no security-scanning tool was detected, leaving a repository hygiene gap without proving the package is unsafe.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The sole workflow uses read-only permissions and has no audited injection or high-severity findings, but all 3 action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.7 || ^4.3 | — | — |
symfony/asset Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
contao/core-bundle Version ^5.7 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.