The MIT license and exact repository match aid transparency, but the project has little adoption evidence and no automated security tooling. Its pre-1.0 status also leaves API compatibility uncertain.
58%
Total Score
100
63
50
The package is about 1 year 3 months old, with 25 releases concentrated within roughly 1 day and none in the last 12 months. This suggests an abandoned or stalled release stream despite the initial burst of activity.
The artifact has no README, tests, or changelog, but the exact version has GitHub release notes and the repository uses GitHub releases. The release notes partly compensate for missing changelog material, while the missing consumer-facing README remains a minor transparency gap.
The linked repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the complete absence of adoption signals provides no outside indication of maturity or community support.
Composer is used for the build, but no security scanning tools were detected. For a security-focused package, that is a meaningful engineering-hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, particularly for a package named and described through its code as security-related.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
iconic/db Version ^0.1.2 | — | — |
doctrine/orm Version ^3.3 | — | — |
symfony/form Version ^7.2 | — | — |
symfony/security-bundle Version ^7.2 | — | — |
doctrine/doctrine-bundle Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.