The project has a complete README, tests, a matching MIT license, and a recent release. Its single maintainer, very small user base, absent security policy, and unpinned workflow actions leave some maintenance and build-hygiene concerns.
72%
Total Score
50
100
89
75
One registry account has publishing access. With a user-owned repository and no organization backing, this indicates a thin maintainer base and greater continuity risk.
The repository is owned by the same user namespace as the package, but the owner is an individual rather than an organization, so there is no visible organizational continuity signal.
The repository recorded no commits and no active maintainers in the last 3 months, which weakens evidence of continuing development despite the recent release and push.
The repository has 2 stars, 0 forks, and 1 watcher. This is limited adoption evidence, but popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 || ^8.0 | — | — |
doctrine/dbal Version ^3.6 || ^4.0 | — | — |
doctrine/doctrine-migrations-bundle Version ^3.7 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.