The license, documentation, and release notes support straightforward use. No install-time scripts reduce surprises, though repository security scanning is absent.
66%
Total Score
50
94
67
One contributor made all two recent commits, concentrating maintenance responsibility entirely in one person; the repository owner is an individual rather than an organization.
Only two commits were recorded in the last three months, which demonstrates some activity but leaves limited evidence of sustained maintenance.
Composer build tooling is present, but no repository security-scanning tool was detected, leaving a maintenance and review gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Both workflows use read-only permissions and contain no reported audit findings, but all 13 analyzed action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.16 || ^3.0 | — | — |
symfony/intl Version ^6.4 || ^7.0 | — | — |
symfony/yaml Version ^6.4 || ^7.0 | — | — |
symfony/dotenv Version ^6.4 || ^7.0 | — | — |
symfony/finder Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.