Its MIT licensing, tests, release notes, and matching repository are reassuring. The 24 runtime dependencies and four unpinned workflow actions add maintenance and build-integrity overhead.
61%
Total Score
50
50
81
67
Twenty-four runtime dependencies create meaningful upgrade and compatibility surface, although the bundle's database, administration, and Symfony integration features make a broad dependency set partly expected.
The repository is owned by a user account rather than an organization, so there is limited visible institutional backing for long-term maintenance.
The package has one release in roughly ten months, with no established release cadence. That limits evidence of sustained maintenance for a dependency.
There were no commits and no active maintainers in the last three months, while the repository was last pushed months earlier. This is concrete evidence of stalled recent maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.