Usable with caveats: this is a mature, organization-backed package with a clear README, license, tests in the repository, and recent releases. Three months without commits, no security policy, and permissive workflow settings reduce confidence in ongoing maintenance and repository hygiene.
65%
Total Score
75
100
94
70
One of four workflows uses pull_request_target, which can increase CI supply-chain exposure if handled incorrectly; no untrusted checkouts or script-injection patterns were detected, limiting the concern.
The repository recorded zero commits and zero active maintainers over the last three months. This is the clearest maintenance concern, although the recent push and release history provide some compensating evidence.
There are only four open issues and two open pull requests, but no issues or pull requests were created or closed in the last month, indicating limited recent interaction.
Composer build tooling is present, but no security scanning tools were detected. For an authentication and access-control bundle, that is a meaningful repository hygiene gap.
The repository has no security policy. For a package implementing authentication, registration, OAuth, and document restrictions, the lack of a documented vulnerability-reporting path lowers transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.7 | — | — |
symfony/form Version ^6.4 | — | — |
pimcore/pimcore Version ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.