The package has a clear README, tests, MIT licensing, and a manageable dependency set. Workflow references are all unpinned, and there is no repository security policy or security scanning, which weakens release hygiene.
68%
Total Score
50
50
94
83
The bundle declares 10 runtime and 5 development dependencies, a fairly broad but understandable dependency surface for a Symfony and Doctrine integration package; it adds some update burden without indicating an unsafe profile by itself.
The registry namespace and repository owner match, and the repository is owned by a user account rather than an organization. This offers limited institutional backing evidence but does not contradict the matching source repository.
The repository has zero commits and zero active maintainers in the last 3 months. That is a meaningful maintenance concern, although the release history shows the project was recently active.
There are no open issues or pull requests and no issue or pull request activity in the last month. With no recent commit activity, this provides no evidence of active maintenance.
Composer build tooling is present, but the repository reports no security scanning tools, leaving automated security hygiene less visible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/config Version ^7.3 | — | — |
yiisoft/strings Version ^2.1 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
symfony/doctrine-bridge Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.