The repository has no security policy or automated security scanning, and its very small footprint limits independent confidence. The long release history and recent publication provide meaningful maintenance evidence.
63%
Total Score
50
70
50
The repository recorded no commits and no active maintainers in the last three months, which conflicts with the recent registry release and raises concern about current source maintenance.
The repository name does not match the package name and its README does not mention the package, creating uncertainty about whether the linked repository directly represents this release.
The repository has 1 star, no forks, and no watchers. Popularity is only supporting evidence, but this provides little independent evidence of broad review or adoption.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful verification gap for a dependency package.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4.14 || ^7.2 | — | — |
symfony/config Version ^6.4.14 || ^7.2 | — | — |
pimcore/pimcore Version ^2026.2 | — | — |
coreshop/pimcore Version ^2026.1 | — | — |
symfony/workflow Version ^6.4.14 || ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.