Documentation and tests are strong, and the MIT licensing is clear. Its one-day history and absent security policy leave little evidence of long-term maintenance or security practice yet.
68%
Total Score
75
81
67
The package defines post-install and post-update scripts, increasing installation-time behavior that consumers should understand; the signal does not show those scripts are harmful.
This is the first release and was published only one day ago, so there is no release track record or established cadence to support long-term maintenance confidence.
There were no commits or active maintainers in the measured three-month window, but the repository is only one day old, so this is a limited track-record concern rather than evidence of abandonment.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any adoption signal adds modest uncertainty for a brand-new package.
Composer build tooling is present, but no security scanning tool was detected, leaving a security-process gap for an identity and authentication service.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.7 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version 8.1.* | — | — |
symfony/asset Version 8.1.* | — | — |
symfony/dotenv Version 8.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.