Healthy and actively maintained, with a clear README, regular releases, organizational backing, and a non-archived repository. Dependence is tempered by all recent commits coming from one contributor, no security policy, and two pull-request workflows requiring extra trust.
78%
Total Score
88
94
63
Two of four workflows use pull_request_target, which can carry elevated trust requirements when processing pull requests. No untrusted checkout or script-injection patterns were detected, partially compensating for the workflow concern.
All 4 recent commits came from one contributor, giving the project a concentrated short-term contributor base. Organizational ownership provides some handoff capacity, but it does not remove the continuity concern.
The repository uses Composer build tooling, but no security scanning tools were detected. The build setup is present; the missing automated security coverage is a modest transparency gap.
No repository security policy was found. This does not show abandonment, but it leaves vulnerability reporting and response expectations undocumented.
Three workflows use read-only permissions, while one workflow declares top-level write permissions. The limited write use is a manageable workflow-governance concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
pimcore/pimcore Version ^2026.2 | — | — |
pimcore/studio-ui-bundle Version ^2026.2 | — | — |
pimcore/studio-backend-bundle Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.