A single contributor made all three recent commits, and every analyzed workflow action is unpinned. Recent releases, repository tests, organization backing, and release notes provide useful counterweight.
78%
Total Score
67
93
75
One contributor made all three recent commits, so maintenance depends heavily on one person. Organization backing partly offsets the handoff risk but does not remove the concentration.
Three commits landed in the last three months, which is evidence of current activity, though the volume is modest for a project with only one active maintainer.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and dependency-monitoring gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for users.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-confidence findings, but all 19 action references are unpinned. The lack of a top-level permissions block is not concerning on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.8 || ^3.1 | — | — |
doctrine/persistence Version ^1.3 || ^2.5 || ^3.1 || ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.