The package includes tests, a changelog, a license, and clear integration documentation. Organization backing and a second active contributor provide useful continuity despite limited repository popularity.
84%
Total Score
100
88
50
The repository uses Composer build tooling, but no security-scanning tool was detected. That is a modest transparency and hygiene gap, not evidence of unsafe code by itself.
No repository security policy was detected, leaving vulnerability-reporting expectations undocumented. This is a maintenance and transparency gap, though it does not outweigh the active project evidence.
Version v0.1.20 is not a stable-major release, so compatibility may still change. It is nevertheless a normal release rather than a prerelease, and the frequent release history partly offsets this concern.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all six action references are unpinned. That weakens build reproducibility and supply-chain hygiene without indicating an immediate severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6 | — | — |
doctrine/dbal Version ^4.4 | — | — |
symfony/cache Version ^6.4 || ^7.4 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
symfony/serializer Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.