Clear documentation, tests, and a security policy make the package easier to adopt. Its very short history and single active contributor leave limited evidence of long-term support.
67%
Total Score
83
100
86
75
Install and update lifecycle scripts add execution during dependency operations, increasing operational complexity compared with a package without such hooks.
The package is only 31 days old, with five releases concentrated within roughly one day. This shows early activity but provides little evidence of sustained maintenance.
All 18 recent commits came from one contributor, creating a real continuity risk. Organization backing helps provide context, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools were detected, leaving less automated coverage for a package involved in database authentication.
The workflow audit completed cleanly with no injection or high-severity findings, but all five analyzed action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 || ^8.0 | — | — |
doctrine/doctrine-bundle Version ^2.13 || ^3.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.0 | — | — |
tacticmedia/rds-auth-middleware Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.