Integrate compatible draw packages in Sonata admin
80%
Total Score
67
100
83
90
The repository is owned by an individual user rather than an organization. That makes the concentrated contributor activity more consequential because there is no demonstrated organizational maintenance handoff.
One contributor made 8 of the 10 recent commits, leaving a concentrated maintenance base. A second contributor remains active, so this is a continuity concern rather than a severe abandonment signal.
The repository has 0 stars, 0 forks, and 1 watcher. This provides little external validation, but popularity is supporting evidence and the active release and commit history compensate for the small audience.
The repository uses Composer build tooling, but no security-scanning tool is reported. Composer is appropriate for the package; the absent scanning is a modest transparency gap.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not by itself evidence that the package is unsafe to use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
draw/sonata-extra-bundle Version ^0.43 | — | — |
symfony/framework-bundle Version ^7.4.0 | — | — |
draw/framework-extra-bundle Version ^0.43 | — | — |
sonata-project/admin-bundle Version ^4.8 | — | — |
symfony/expression-language Version ^7.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.