Clear documentation, tests, licensing, and a matching repository make integration straightforward. No commits in the last three months, absent security scanning and policy, and four unpinned actions add maintenance and supply-chain review risk.
68%
Total Score
50
89
75
There were zero commits and zero active maintainers in the last three months. This weakens evidence of current maintenance despite the package's earlier release history.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little independent evidence of adoption or community support.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance concern.
The repository has no security policy. This leaves vulnerability reporting and response expectations undocumented, though it is not by itself evidence of unsafe code.
Both workflows were analyzed successfully with no audit findings and no untrusted checkout or script-injection paths, but all four action references are unpinned. That leaves avoidable workflow supply-chain drift risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
yiisoft/strings Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.