Security documentation is absent, and all three workflow actions are unpinned. Licensing, tests, release notes, and repository ownership provide useful transparency, but the dependency set is broad and increases maintenance overhead.
70%
Total Score
75
50
100
50
The package declares 59 runtime dependencies across framework, database, messaging, search, and infrastructure components, which creates meaningful upgrade and compatibility overhead.
post-install-cmd and post-update-cmd scripts run during dependency operations, creating extra execution and maintenance exposure compared with a package without lifecycle hooks.
No commits or active maintainers were recorded in the last three months, a significant maintenance warning even though the repository received a recent push associated with the release.
No repository security policy was found, leaving the project's vulnerability-reporting process undocumented.
The single workflow was fully analyzed with no untrusted checkout, injection, or audit findings, but all 3 action references are unpinned, reducing build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.28.0 | — | — |
doctrine/orm Version 3.6.* | — | — |
symfony/flex Version ^2.11.0 | — | — |
symfony/form Version 8.1.* | — | — |
symfony/intl Version 8.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.