The package has a clear MIT license, a useful README, and repository tests. Long release intervals and the absent security policy reduce confidence in ongoing care.
55%
Total Score
50
70
50
The package is about 928 days old but has only three releases, with one release in the past 12 months and a median interval of about 360 days. This indicates slow maintenance rather than abandonment by itself.
The repository recorded zero commits and zero active maintainers in the past three months. That is a meaningful maintenance concern, even though the repository is not archived.
Composer is used for the build, but no security-scanning tooling was detected. This leaves a transparency and dependency-review gap.
The repository has no security policy. Consumers have no documented reporting path or published security-handling expectations.
The assessed release is stable rather than a prerelease, which supports predictable adoption. However, the registry reports version 2.0 as latest while this assessment concerns 3.0, creating some release metadata uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cron/cron Version ^1.0.1 | — | — |
doctrine/orm Version ^3.6 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^8.0 | — | — |
symfony/console Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.