Universal service provider for Gember Event Sourcing (gember/event-sourcing)
68%
Total Score
caution
Usable with caveats: all workflow actions are unpinned and the project relies on one active contributor.
The package declares 16 runtime dependencies, including several framework, database, messaging, and serialization adapters. That broad integration surface increases upgrade coordination, though it is consistent with the package's service-provider role.
The package is 511 days old with 12 releases and a latest release on 2026-08-24; only two releases occurred in the last 12 months, suggesting slower recent delivery but not abandonment.
No repository security policy was found, so users have no documented vulnerability-reporting path. This is a transparency gap for a package intended for application integration.
Version 0.11.0 is not a stable major release, so compatibility may still change before 1.0. It is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it avoids top-level write permissions. However, both of its two action references are unpinned, leaving them exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/uid Version ^7.1|^7.2|^8.0 | — | — |
doctrine/dbal Version ^4.2 | — | — |
psr/container Version ^2.0 | — | — |
symfony/cache Version ^7.1|^7.2|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.