The license and consumer documentation are present, and the repository remains active and unarchived. Long-term resilience is less clear because releases are infrequent, one contributor made all recent commits, and no security policy is published.
67%
Total Score
83
86
50
The package includes a LICENSE file and repository license, but the manifest declares LGPL-3.0-or-later while the detected artifact license is GPL-3.0. That mismatch reduces licensing transparency.
The package has only 3 releases over 507 days, with a median interval of about 211 days and 2 releases in the last 12 months. The latest release is recent, but the sparse cadence provides limited evidence of sustained evolution.
One contributor made all 6 commits in the last 3 months. Organization backing provides some handoff capacity, but no second active contributor is visible in the collected activity.
The repository has no published security policy, leaving no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^5.4 || ^6.4 || ^7.4 | — | — |
doctrine/orm Version ^2.0 || ^3.0 | — | — |
doctrine/dbal Version ^3.6 || ^4.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.4 | — | — |
symfony/routing Version ^5.4 || ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.