The package has tests, a README, release notes for this version, and an MIT declaration. Its single-user ownership, absent security policy, and zero repository adoption add little resilience.
42%
Total Score
25
57
50
The latest release was in November 2021, with no releases in the last 12 months despite eight releases overall. This indicates prolonged maintenance inactivity and materially increases abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release gap. This is a significant maintenance concern, though the repository is not marked archived.
Only one registry maintainer is listed. The linked repository is owned by a user rather than an organization, so there is no provided organizational backing to compensate for the thin maintainer base.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that the repository clearly documents and supports this package.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these figures provide no supporting evidence of broad adoption or community resilience.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.7 | — | — |
symfony/yaml Version ^5.3 | — | — |
symfony/validator Version ^5.3 | — | — |
symfony/property-access Version ^5.3 | — | — |
doctrine/doctrine-bundle Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.