Documentation, tests, and release notes make integration straightforward. MIT licensing and no install scripts reduce adoption friction, while the missing security policy leaves a smaller transparency gap.
68%
Total Score
75
93
75
The repository had no commits and no active maintainers in the last three months. This suggests maintenance has slowed despite the broader release history.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance-process gap, not evidence of a security failure.
The repository has no security policy. For a library handling message-bus integrations, this leaves vulnerability-reporting expectations less explicit.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.11 || ^3.0 | — | — |
symfony/lock Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
doctrine/dbal Version ^2.13 || ^3.0 || ^4.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
symfony/config Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.