The package includes tests, a clear README, and a matching MIT license. Its small repository has little community activity, and the workflow relies on unpinned actions.
68%
Total Score
75
88
75
There were no commits and no active maintainers in the last three months, which leaves recent maintenance capacity unproven despite the recent release.
The repository has zero stars and one fork, so there is little visible community adoption or outside support; this is supporting caution rather than a verdict by itself.
Composer is used as the build tool, but no security scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed and has job-level permission scoping with no detected injection or high-severity findings, but all 10 action references are unpinned, weakening build reproducibility and supply-chain controls.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/validator Version ^6.0|^7.0 | — | — |
symfony/property-info Version ^6.0|^7.0 | — | — |
symfony/dependency-injection Version ^6.0|^7.0 | — | — |
mark-gerarts/auto-mapper-plus Version ^1.4.2 | — | — |
phpdocumentor/reflection-docblock Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.