Tests, release notes, matching repository, and an MIT license provide useful transparency. The short release burst and no recent commits leave maintenance continuity uncertain; all six workflow actions are unpinned.
60%
Total Score
50
90
The package is about 10 months old but all five releases arrived within roughly 10 days, with no later registry releases. That brief burst provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Earlier release activity partly offsets this, but the current maintenance signal is weak.
Both workflows were analyzed without dangerous triggers or audit findings, and one uses read-only permissions. However, all six action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
doctrine/common Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.