Healthy and reasonable to depend on. It has regular releases, an active non-archived repository, tests and documentation, and organizational backing; the main caveats are a single recent contributor and limited repository security controls.
82%
Total Score
75
50
93
63
The bundle declares 27 runtime dependencies across Symfony, Doctrine, API Platform, and related components. This is a substantial dependency surface that increases upgrade and compatibility work, though it is consistent with a full payment integration bundle.
The package runs a post-autoload-dump install-time script. This is an operational consideration for consumers, but the signal does not show that the script is unsafe or unusually invasive.
One contributor made all recorded commits in the last 3 months. Organizational ownership provides some handoff capacity, but the observed contributor base is still concentrated.
Only one commit was recorded in the last 3 months, so direct commit activity is light. Recent releases and four merged pull requests partly compensate for this, but the maintenance signal is not as strong as the release cadence alone suggests.
The repository uses Composer build tooling but reports no security-scanning tools. This is a transparency and preventive-control gap, though it is not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1.4 || ^2.0.0 || ^3.0.0 | — | — |
twig/twig Version ^3.8 | — | — |
symfony/uid Version ^6.4 || ^7.4 | — | — |
doctrine/orm Version ^2.18 || ^3.2 | — | — |
symfony/lock Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.