The package is clearly documented and tested, with a permissive license and release notes. Workflow references are unpinned, and the repository has no security policy or scanning, leaving some hygiene gaps.
86%
Total Score
100
94
75
Composer is used as the build tool, but no security scanning tool was detected. The absence of scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy. This does not show a maintenance failure, but it reduces transparency about how vulnerabilities are reported and handled.
The single workflow was fully audited with no injection or high-confidence findings, and it uses no broad top-level write permissions. All 3 action references are unpinned, which is a supply-chain hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5.3 || ^3.0 | — | — |
symfony/config Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/process Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
php-task/php-task Version ^3.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.