Usable with caveats: the package is actively published, backed by a matching organization repository, and has basic testing and security tooling. It is very young, has only one active contributor, and its workflows lack explicit token permissions and a security policy.
68%
Total Score
75
50
88
80
The package declares 14 runtime dependencies, including framework, database, security, and serialization components. This is a relatively broad dependency surface for a young package and increases upgrade and compatibility obligations.
The artifact includes a README and tests, and the repository also has tests and uses GitHub Releases. The README is only 20 characters and there is no changelog, limiting consumer guidance, but absent changelogs are not required in the published artifact.
One contributor made 100% of the two commits in the last three months. This concentration creates continuity risk, although the repository is organization-owned and therefore has some potential for handoff.
The repository has two commits in the last three months, both from one active maintainer. Recent activity exists, but the low volume suggests maintenance capacity is still limited.
The repository has no security policy. This is a transparency and vulnerability-reporting gap for a package that includes framework, database, and security-related functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.12|^3.2 | — | — |
symfony/lock Version ^7.4 | — | — |
symfony/config Version ^7.4 | — | — |
symfony/console Version ^7.4 | — | — |
symfony/serializer Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.