The project has a clear README, tests, release notes, matching source repository, and a valid MIT license. Maintenance has gone quiet for about nine months, while all four workflow actions are unpinned and no security scanning or security policy is present.
62%
Total Score
50
50
83
83
The package declares 35 runtime dependencies, including substantial Symfony, Doctrine, and administration components; this increases upgrade and transitive-dependency maintenance burden.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is limited evidence of organizational continuity.
There were no commits and no active maintainers in the three months before collection, consistent with roughly nine months since the last recorded push and raising maintenance risk.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external validation or visible community support.
Composer build tooling is present, but no security scanning tools were detected, leaving an avoidable security-maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.