The package has strong documentation, tests, a matching repository, and a clear MIT license. Its broad dependency set, absent security policy, and unpinned workflow actions add maintenance and build-reproducibility concerns.
58%
Total Score
50
50
75
83
The package declares 27 runtime dependencies, including framework, database, admin, and several project-specific bundles; this broad dependency surface increases integration and maintenance burden.
The repository is owned by a personal GitHub account rather than an organization, so the short ownership context does not demonstrate organizational maintenance capacity.
Only one release exists, published about 10 months ago, so there is little release history to demonstrate maturity or continued maintenance.
There were no commits and no active maintainers in the past three months, leaving current maintenance responsiveness unproven for a package with only one release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of external adoption provides no additional maturity signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.