Clear documentation, tests, and licensing make integration easier. Maintenance evidence is thin: this is the only release and there have been no commits in about nine months. Workflow references are all unpinned, and the repository has no security policy or scanning tools.
58%
Total Score
50
79
67
The package has only one release, 0.0.1, published about ten months ago, so there is little release history to demonstrate ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly nine months since the last push and raising abandonment risk.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented security reporting process; this is a hygiene gap rather than evidence of unsafe code.
The release is not a stable major version, remaining at 0.0.1, which signals an immature API despite it not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.