Clear licensing, tests, and release notes support adoption. The repository lacks security scanning, and all four workflow actions are unpinned, so build integrity deserves extra care.
78%
Total Score
89
83
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this offers little external adoption signal.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, or audit findings, and one workflow uses read-only permissions. However, all four action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
symfony/config Version ^7.3 | — | — |
nette/php-generator Version ^4.1 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.