Usable with caveats: the package has a long, active release history, clear source backing, tests, and a stable release. Recent repository work is very limited and concentrated in one contributor, with no security policy or scanning to strengthen maintenance transparency.
72%
Total Score
63
50
89
90
The package declares 45 runtime dependencies and 8 development dependencies, indicating a substantial dependency surface that increases maintenance exposure, although this is consistent with its broad backend and frontend framework role.
All 3-month commit activity came from one contributor, creating concentration risk. Organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe failure.
Only 1 commit was recorded in the last 3 months from 1 active maintainer, despite the recent release activity. That mismatch leaves current development depth unclear and suggests slow source-level maintenance.
There were no new or closed issues or pull requests in the last month, and three pull requests remain open. This gives limited evidence of active public issue handling, though the issue count itself is unknown.
The repository has only 3 stars and 3 forks, which offers little community validation. Low popularity is supporting evidence rather than a decisive health problem for an organization-backed package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4 | — | — |
doctrine/orm Version ^2.20 | — | — |
symfony/form Version ^6.4||^7.4 | — | — |
symfony/yaml Version ^6.4||^7.4 | — | — |
doctrine/dbal Version ^3.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.