Usable with caveats: it has a long release history, recent stable releases, organizational backing, and repository tests, but no commits in the last three months and limited security process visibility warrant review before adoption.
70%
Total Score
75
50
93
67
Seven runtime dependencies, including Doctrine and Symfony components, create a meaningful compatibility surface for this framework bundle. The profile is plausible for the package's stated function but warrants normal dependency review.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release and push are recent, the lack of recent development activity is a real maintenance concern.
The repository uses Composer build tooling but has no detected security-scanning tooling. Build support is present, while security-process visibility is limited.
No repository security policy was found. For a bundle that records database changes and may handle user-linked audit data, this is a transparency gap.
The single workflow has no top-level token permissions declaration. No write permissions were detected, which limits the concern, but explicit least-privilege configuration would provide stronger assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.13|^3.0 | — | — |
doctrine/dbal Version ^3.2|^4.0 | — | — |
symfony/console Version ^6.4 | ^7.0 | — | — |
symfony/security-bundle Version ^6.4 | ^7.0 | — | — |
doctrine/doctrine-bundle Version ^2.9|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.