The single active contributor is the main limitation, and all nine workflow actions are unpinned. Regular releases, a current release note, tests, security scanning, and read-only workflow permissions provide strong evidence of ongoing care.
82%
Total Score
83
100
100
75
The package uses post-install and post-update scripts. These are normal for a Composer application template, though they make installation behavior more consequential than a library with no lifecycle scripts.
One contributor made all 8 commits in the last three months, giving the project a concentrated bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts, injection findings, or high-confidence audit issues. All 9 action references are unpinned, leaving avoidable action-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
doctrine/orm Version ^3.3 | — | — |
symfony/flex Version ^2 | — | — |
symfony/form Version ~8.1.0 | — | — |
symfony/intl Version ~8.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.