Healthy and suitable to depend on, with strong release history, clear ownership, and a well-documented package. Repository activity has been quiet for about three months and the project lacks a security policy, so monitor future maintenance.
78%
Total Score
50
100
67
Only one registry account has publish access, creating some continuity risk; this is partly offset by the matching source repository and the package's long release history.
The registry namespace and repository are owned by the same individual, so ownership is consistent, though there is no organization backing to broaden the maintainer base.
The repository recorded no commits and no active maintainers during the last three months, which is a real maintenance concern, although the recent release history and recent repository push provide compensating evidence.
There were no new or closed issues or pull requests during the last month, leaving current responsiveness uncertain; the seven open pull requests and regular package releases soften but do not remove this concern.
No security policy was found in the repository, leaving the process for reporting vulnerabilities unclear.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-45592 damienharper/auditor-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.2.6. | 0.0.0 - 5.2.6 | High |
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.2 | — | — |
symfony/lock Version ^8.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/asset Version ^8.0 | — | — |
twig/intl-extra Version ^3.3 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.