The package has a clear license, a stable release, and no install-time scripts. Its empty recent commit window, absent tests, and missing security policy leave maintenance and review risk.
65%
Total Score
50
100
81
75
A README is present, but the package and repository report no tests or changelog. Missing tests reduce confidence for a library, while the absent changelog is a smaller documentation gap.
The repository recorded zero commits and zero active maintainers in the last three months, despite eight registry releases in the last year. This weakens evidence of ongoing source maintenance.
The repository has no stars, one fork, and one watcher. Low adoption is supporting evidence of a small project, but it does not by itself make the package unsafe to depend on.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a review and maintenance weakness rather than a severe risk on its own.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.15 || ^3.0 | — | — |
symfony/validator Version ^6.4 || ^7.4 | — | — |
jms/serializer-bundle Version ^5.4 || ^6.0 | — | — |
pagerfanta/pagerfanta Version ^4.2 | — | — |
symfony/property-access Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.