The package includes tests, a README, an MIT license, and release notes for this version. Its workflow uses six unpinned actions, and the project has no security policy, leaving maintenance and build hygiene concerns.
56%
Total Score
50
79
75
The latest release was in October 2022, nearly four years ago, with no releases in the last 12 months. This is strong evidence of stalled maintenance for a dependency.
Only one registry account can publish releases, which creates a thin publishing base. The repository is also owned by an individual, so no organizational backing compensates for that concentration.
The repository has zero stars and zero forks, with one watcher. Popularity is not required for health, but these numbers provide little supporting evidence of adoption or community resilience.
The repository has no security policy. This weakens disclosure transparency, although it is not by itself evidence that the package is unsafe.
The workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all six action references are unpinned. That leaves avoidable build-supply-chain drift despite the otherwise clean audit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.11 | — | — |
symfony/config Version ^5.2 || ^6.0 | — | — |
symfony/http-kernel Version ^6.0 | — | — |
symfony/property-info Version ^6.0 | — | — |
symfony/property-access Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.