Clear documentation, tests, a release note, and an MIT license make integration straightforward. The tiny audience and absent security policy leave less independent oversight.
64%
Total Score
50
100
83
75
A single registry maintainer is consistent with the repository being user-owned, but it also indicates limited publishing redundancy.
The repository is owned by an individual user rather than an organization, so the single registry maintainer and limited visible backing provide little redundancy.
The package has existed since October 2016 but has only seven releases, with no releases in the last 12 months and a median interval of about 371 days. That indicates a slow maintenance cadence and raises abandonment concerns.
There were no commits and no active maintainers in the three months measured, despite the repository not being archived. This weakens evidence of ongoing maintenance.
The repository has zero stars, forks, and watchers, so there is little visible community adoption or independent scrutiny. Popularity is supporting evidence rather than a verdict, so this is a moderate concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5|^3.0 | — | — |
symfony/form Version ^4.0|^5.0|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.