Data Fixtures for all Doctrine Object Managers
45%
Total Score
83
100
89
83
The package is flagged as borrowing the identity of doctrine/lexer, with borrows_lookalike_identity true and no self-described fork or integration evidence. Although artifact overlap is 0.0, this creates a serious risk that consumers intended to install the lookalike package.
There were no commits and no active maintainers in the last 3 months. This is a maintenance warning, although the recent release history and three merged pull requests provide some compensating evidence.
All six workflows were analyzed without failures and have no untrusted checkouts, script injection, or top-level write permissions. However, all 12 action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image, which weakens build reproducibility and workflow supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2 || ^3 | — | — |
doctrine/persistence Version ^3.1 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.