The repository includes a full test suite and security scanning, while its sole workflow uses an unpinned action. Organization backing and a matching repository add useful context.
67%
Total Score
75
94
50
The package is less than one day old with three releases, so there is not enough history to demonstrate sustained maintenance or release stability.
The repository shows zero commits and zero active maintainers in the last three months, but the package itself is newly created, so this is limited evidence rather than clear abandonment.
The only workflow was fully analyzed with no dangerous findings, but its one action reference is unpinned, leaving a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.3 | — | — |
symfony/yaml Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
symfony/translation Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.