The package includes tests, a changelog, a matching repository, and consistent MIT licensing. Maintenance has slowed recently, while one maintainer, no security scanning, and mostly unpinned workflow actions add ongoing risk.
65%
Total Score
50
89
75
Only one registry account can publish the package. That is a thin publishing base for a user-owned project, although the release history shows that this maintainer has continued publishing.
The repository is owned by a user rather than an organization, so there is no organizational backing to offset the single-maintainer publishing model.
The repository recorded zero commits and zero active maintainers in the last three months. This suggests maintenance has recently stalled, despite the release on May 5, 2026.
The repository has zero stars and forks and one watcher. Popularity is not decisive, but these figures provide little supporting evidence of broad adoption or external review.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a maintenance and transparency gap for a package with 26 runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.3 | — | — |
symfony/yaml Version ^7.2|^6 | — | — |
doctrine/dbal Version ^3.9 | — | — |
nesbot/carbon Version ^3.8 | — | — |
symfony/asset Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.