Documentation, tests, release notes, and a security policy provide good project transparency. The small audience and lack of security scanning add modest maintenance and hygiene concerns.
67%
Total Score
50
89
100
The registry namespace and repository owner match, but both are owned by a single user rather than an organization. This offers direct ownership consistency but limited evidence of institutional backing.
There were zero commits and zero active maintainers in the last three months. Although the latest release shows recent work, the current inactivity raises a real risk that maintenance has slowed or stopped.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very small numbers provide little evidence of broad community review or shared maintenance.
The project uses Composer and Task for builds and has no detected security-scanning tools. The missing scanning is a modest hygiene gap, not evidence that the package is unsafe.
Both workflows were fully analyzed with no audit findings or untrusted checkouts, but all 13 action references are unpinned and one workflow grants top-level write access. This is a meaningful reproducibility and workflow-hygiene concern, though no dangerous trigger or sink was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.16 || ^3.0 | — | — |
symfony/yaml Version ^6.4 || ^7.1 | — | — |
symfony/routing Version ^6.4 || ^7.1 | — | — |
symfony/validator Version ^6.4 || ^7.1 | — | — |
symfony/serializer Version ^6.4 || ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.