It also has clear licensing, repository tests, release notes, and no install-time scripts. Maintenance is concentrated in one contributor, security-policy coverage is absent, and both workflow actions are unpinned, but organizational backing and a clean workflow audit reduce the concern.
82%
Total Score
83
94
67
One contributor made all 2 commits in the last 3 months, so recent maintenance has a narrow individual base. The organization-owned project provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. This leaves vulnerability-reporting expectations undocumented, which is a minor transparency gap for a dependency library.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of the two referenced actions are unpinned, leaving their build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.9 | — | — |
cuyz/valinor Version ^2.4 | — | — |
doctrine/orm Version ^3.6 | — | — |
lcobucci/jwt Version ^5.6 | — | — |
symfony/lock Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.