Usable with caveats: the package is actively released and backed by an organization, but it has no tests or changelog, relies on one recent contributor, and declares a proprietary license. Confirm licensing and maintenance expectations before adopting it.
63%
Total Score
67
50
81
50
The package declares 13 runtime dependencies, including Symfony, Doctrine, and extension packages, creating a relatively broad dependency surface for a bundle. The profile is coherent with its stated Symfony and Doctrine function, so this is a manageable rather than severe concern.
The package declares a proprietary license and has no license file in the artifact or repository, which creates a meaningful restriction and transparency concern for dependency adoption.
A README is present, but neither the package nor its repository contains tests or a changelog. For an application-facing Symfony bundle, the lack of visible tests is a real maintenance and regression concern.
All 4 recent commits came from one contributor. The organization-owned repository provides some ability to hand maintenance to others, but no second active contributor is shown, so concentration remains a concern.
The repository received 4 commits in the last 3 months from one active maintainer, showing recent work but limited ongoing activity and contributor depth.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version ^8.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/console Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.