Clear documentation, tests, and licensing make integration straightforward. A single publisher, no security scanning, and unpinned workflow actions leave less maintenance and build transparency than a mature dependency.
68%
Total Score
63
100
83
75
Only one registry account has publish access, creating a thin publishing base and increasing continuity risk if that maintainer becomes unavailable.
The repository is owned by an individual user rather than an organization, so the single-maintainer publishing model is not compensated by visible organizational backing.
No commits or active maintainers were recorded in the last three months, indicating a recent maintenance pause despite the strong registry release cadence.
The repository has zero stars and forks and one watcher. This is weak supporting evidence of adoption, but popularity alone does not establish poor package health.
Composer build tooling is present, but no security scanning tools are configured, leaving a transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.14 || ^3.0 | — | — |
symfony/yaml Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/finder Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/console Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.