The package is licensed, has repository tests, and is not archived. The source is substantial, but its security policy and scanning coverage are absent.
42%
Total Score
50
50
81
50
This is the only release, published in January 2023, with no releases in the last 12 months. The repository was pushed later, but the registry shows no continuing release maintenance.
There were zero commits and zero active maintainers in the three months before collection. Combined with one registry release, this is strong evidence of currently inactive maintenance.
The release declares 25 runtime dependencies, including several framework and application-layer components. That broad dependency surface increases upgrade and compatibility burden for a package with only one release.
Composer build tooling is present, but no security scanning tools were detected. That weakens the project's ongoing supply-chain oversight.
The repository has no security policy. This leaves vulnerability reporting and response expectations undocumented for a package with a large runtime dependency surface.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
psr/cache Version ^1.0|^2.0|^3.0 | — | — |
doctrine/orm Version ^2.13 | — | — |
psr/container Version ^1.0|^2.0 | — | — |
symfony/config Version ^4.4|^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.