Licensing and install behavior are straightforward. The repository includes tests, a substantial README, and release notes, but this release was published today, so sustained maintenance is not yet demonstrated; all eight workflow actions are unpinned.
78%
Total Score
75
100
88
75
This is the first release and it was published today, so there is not enough history to demonstrate a sustained release cadence. That is uncertainty for a new package rather than evidence of abandonment.
No commits or active maintainers were recorded in the last three months, but the package and repository were created today, making this measure unavailable for proving ongoing maintenance rather than a strong abandonment signal.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a maintenance and transparency gap, but it is not severe for a newly published small package.
The single workflow was fully analyzed and has no untrusted checkout or script-injection findings, but all eight action references are unpinned. The low-confidence cache-poisoning finding is hygiene evidence only and does not independently establish a serious risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6 | — | — |
psr/container Version ^1.1.2 || ^2.0.2 | — | — |
doctrine/event-manager Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.