The package has thorough documentation, tests, a changelog, and a matching MIT license. Its project is brand new with only two releases, no adoption evidence, no security policy, and nine unpinned workflow actions.
64%
Total Score
50
50
75
50
The package declares 14 runtime dependencies, including several Symfony components and Doctrine integrations; this is substantial coupling for a young package, though the dependency set fits its stated framework role.
The package is backed by a matching individual-owned repository rather than an organization, so the single registry maintainer does not represent a broader project team.
The project is newly published, with only two releases on the same day and no meaningful release history yet; this leaves maintenance maturity unproven.
The repository has zero stars, forks, and watchers. For a project released today this is not proof of poor quality, but it provides no external adoption evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
doctrine/dbal Version ^2.13 || ^3.0 || ^4.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/console Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.