The stable major version, MIT licensing, tests, and repository backing help. The source repository does not name this package in its README and has no security policy, reducing transparency.
52%
Total Score
75
100
81
75
The latest registry release was January 26, 2021, with no releases in the last five years and eight months. This long publishing gap is a meaningful maintenance concern, although the linked repository is not archived.
The repository recorded zero commits and zero active maintainers in the last three months. That recent inactivity raises maintenance risk, even though the repository was pushed in May 2026.
The repository name does not match the package name and its README does not mention the package. That makes the repository-to-package relationship less transparent and warrants caution.
Composer is used as a build tool, but no security-scanning tools are configured. The missing scanning is a modest repository hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is less serious than an archived repository or withdrawn release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version * | — | — |
zendframework/zend-json Version * | — | — |
symfony/framework-bundle Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.