The package includes tests, release notes, a clear MIT declaration, and security scanning. Repository activity has been quiet for three months, while all four workflow actions are unpinned and no security policy is published.
62%
Total Score
75
86
75
The package has 19 releases over about two and a half years, but none in the last 12 months. That recent pause lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months. Together with the absence of registry releases in the last 12 months, this indicates a meaningful maintenance slowdown.
No security policy is published in the repository. That is a transparency and vulnerability-reporting gap, though it is not evidence that the package is unsafe.
v0.9.1 is not a prerelease, although the package remains below a stable major version. This is a modest maturity concern rather than a severe adoption barrier.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all four action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
api-platform/core Version ^3.2.12 || ^3.3 || ^4.0 | — | — |
rekalogika/mapper Version ^1.13.3 || ^1.14 || ^2.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 | — | — |
doctrine/collections Version ^2.2 | — | — |
symfony/security-core Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.