The project has recent commits from four contributors, an active repository, tests, and a security policy. Its dependency set is sizable, and the build workflows use unpinned action references.
61%
Total Score
100
50
81
67
The release declares 22 runtime dependencies, including a substantial Symfony and Doctrine stack. This increases upgrade and compatibility complexity, but does not by itself indicate abandonment.
The manifest declares MIT, but the artifact license file is detected as GPL-3.0; although license files are present, the mismatch requires clarification before depending on the release.
post-install-cmd, post-root-package-install, and post-update-cmd scripts run during dependency operations. Install-time execution increases integration and supply-chain exposure compared with a package without lifecycle hooks.
The project uses Make and Composer and has a security policy, but no security-scanning tooling was detected. The missing automated scanning is a modest hygiene concern rather than evidence of unmaintained code.
The assessed version is explicitly 2.0.0-alpha2, while the registry profile lists 0.12.1 as latest and marks recent releases stable. That inconsistency and the alpha status make this release less mature for adoption.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
baikal/core Version dev-master as 2.0.0-alpha1 | — | — |
doctrine/orm Version ~2.2,>=2.2.3,<2.5 | — | — |
doctrine/dbal Version ~2.5 | — | — |
symfony/symfony Version ~2.6 | — | — |
twig/extensions Version ~1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.