Its MIT licensing, clear documentation, release notes, and comprehensive tests make adoption easier. Repository work has been quiet for 3 months, while all workflow actions are unpinned and no security policy or scanning is provided.
70%
Total Score
50
100
94
83
The registry and repository are owned by the same individual account, so ownership is consistent. This does not provide organization-level maintenance redundancy.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was January 25, 2026. That quiet period is a real maintenance concern despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, so the process for reporting vulnerabilities is unclear. This is a transparency gap, though it is not evidence of a vulnerability by itself.
The only workflow was fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions. However, both of its action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.19|^3.0 | — | — |
symfony/config Version ^6.4|^7.0 | — | — |
symfony/framework-bundle Version ^6.4|^7.0 | — | — |
symfony/dependency-injection Version ^6.4|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.