Its README, changelog, repository tests, and clear package match make adoption easier. The declared OSL-3.0 license differs from the repository's detected MIT license, and workflow actions are unpinned.
80%
Total Score
100
88
100
The manifest declares OSL-3.0, while the repository license file is detected as MIT; because the detected license does not match the declaration, licensing should be clarified before adoption.
The project uses Composer and Robo build tooling, but no security-scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
The only workflow was fully analyzed with no injection or high-confidence audit findings, but both action references are unpinned. The workflow has no top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rhumsaa/uuid Version ~2.4 | — | — |
symfony/yaml Version ~2.8.7|~3.0.7|~3.1.1|~3.2 | — | — |
doctrine/dbal Version ~2.0 | — | — |
jms/serializer Version ~1.0 | — | — |
symfony/config Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.