Tests, documentation, and organizational ownership provide useful support. The package is still very new, has had no recent commits, and its workflow uses unpinned actions, so maintenance and build reproducibility remain concerns.
61%
Total Score
50
79
75
The repository recorded no commits and no active maintainers in the last 3 months, while its last push coincides with the initial release period. This is a meaningful maintenance concern for a package only months old.
The package is 211 days old with only two releases, both published within hours of each other. This provides limited evidence of an established maintenance pattern.
The repository uses Make and Composer build tooling, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
Version v0.0.2 is not from a stable major version, indicating an immature API and a higher likelihood of breaking changes. It is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, but all 3 action references are unpinned. That weakens build reproducibility without indicating a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6 | — | — |
symfony/validator Version ^7.0 || ^8.0 | — | — |
symkit/crud-bundle Version ~0.0.1 | — | — |
symkit/form-bundle Version ~0.0.1 | — | — |
doctrine/doctrine-bundle Version ^2.11 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.