The project has a clear README, a recent release with notes, and an active organization behind it. Maintenance has since gone quiet for nearly two years, while security policy and action pinning are limited.
58%
Total Score
67
100
88
75
The package has 24 releases over more than 12 years, but none in the last 12 months; the latest release was nearly two years ago. This materially raises maintenance risk.
There were no commits and no active maintainers in the last three months, reinforcing the evidence that development has stalled since the last release.
Only one issue is open and there were no recent issues or pull requests; this is consistent with a quiet project but does not demonstrate active support.
The repository uses Composer and Make, but no security-scanning tools were detected. The build tooling is useful, while the missing scanning is a modest transparency gap.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.2.3 || ^3.0 | — | — |
symfony/config Version ^5.0 || ^6.0 | — | — |
symfony/console Version ^5.0 || ^6.0 | — | — |
symfony/validator Version ^5.0 || ^6.0 | — | — |
symfony/http-kernel Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.