Tests, a substantial README, MIT licensing, and release notes support adoption. Organization backing and recent commits help, but maintenance is concentrated and the CI workflow lacks pinned action versions and a security policy.
68%
Total Score
83
83
50
The package has 24 releases since March 2019, but none in the last 12 months despite a 22-day median release interval, indicating a meaningful recent slowdown.
One contributor made all three commits in the last three months, creating concentration risk; organization ownership provides some capacity to hand maintenance off.
The project uses Composer build tooling, but no security scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 15 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 || ^3.0 | — | — |
symfony/lock Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/messenger Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/serializer Version ^5.4 || ^6.4 || ^7.0 | — | — |
ramsey/uuid-doctrine Version ^1.5 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.