Usable with caveats: this is a newly published Symfony bundle with clear documentation, tests in its repository, licensing, and an active release workflow. Its maintenance history is too short to establish durability, and several CI workflows use broad or risky permissions that warrant review before adoption.
67%
Total Score
83
50
89
75
Seven workflows were analyzed; one uses pull_request_target and another uses an untrusted checkout in a workflow_run context. No script injection was detected, but these patterns increase CI supply-chain exposure and deserve review.
The bundle declares 21 runtime dependencies, including multiple Symfony, Doctrine, Twig, and UI components. That breadth is plausible for the documented admin bundle, but it increases upgrade and compatibility surface.
The package is 0 days old with only 2 releases, both published within about 8 hours. This shows initial activity but provides little evidence of long-term maintenance or release stability.
The repository reports 0 commits and 0 active maintainers over the last 3 months. Because the package is newly created, this mainly reflects insufficient history rather than proven abandonment, but maintenance capacity remains unestablished.
The repository has 0 stars, forks, and watchers. For a package released only hours ago this is unsurprising, but it provides no external adoption evidence yet.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.12 | — | — |
doctrine/orm Version ^2.15 || ^3.0 | — | — |
symfony/form Version ^7.4 || ^8.0 | — | — |
symfony/yaml Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.