Strong documentation, release notes, repository tests, and security tooling improve transparency. The project is only four days old, has no recorded commits in three months, and its CI audit exposes an untrusted checkout alongside a high-confidence template-injection warning.
52%
Total Score
75
50
94
67
All 7 workflows were analyzed, but the audit found an untrusted checkout in a workflow_run workflow and a high-confidence template-injection finding in that workflow; all 19 action references are unpinned, adding supply-chain exposure.
The package declares 23 runtime dependencies for a substantial Symfony and Doctrine page-builder bundle; this adds maintenance surface, but the profile is consistent with the package's described functionality.
The package is only 4 days old but already has 9 releases, showing active initial publishing while providing too little history to establish long-term maintenance.
The repository records 0 commits and 0 active maintainers over the past 3 months. Because the project is only 4 days old, this is partly explained by its age but still leaves maintenance capacity unproven.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 | — | — |
symfony/uid Version ^7.4 || ^8.0 | — | — |
doctrine/orm Version ^3.7 | — | — |
symfony/form Version ^7.4 || ^8.0 | — | — |
symfony/yaml Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.