The repository is active, organization-backed, and has tests plus a clear README. Keep in mind that the release metadata is inconsistent with the requested alpha version, and workflow hygiene needs attention.
67%
Total Score
100
100
88
67
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner lowers assurance modestly without showing a maintenance failure.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, but the organization backing and active maintenance partly offset it.
The assessed release is labeled v8.0.0-alpha.2, while the collected profile reports v5.5.0 as the latest stable version and says the release is not a prerelease. This inconsistency reduces confidence in release maturity and metadata accuracy.
The sole workflow has one high-confidence template-injection finding and its only action use is unpinned. No pull_request_target, workflow_run, untrusted checkout, or script-injection path was found, so this is a workflow hygiene concern rather than a severe supply-chain risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/migrations Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.