The package includes a substantial test suite, clear documentation, an MIT license, and a matching repository. Its broad dependency set, absent security policy, fully unpinned workflow actions, and lack of recent commits reduce confidence in ongoing maintenance.
68%
Total Score
50
50
94
83
The package declares 35 runtime dependencies, including several Symfony, Doctrine, and ecosystem integrations. This broad dependency surface increases compatibility and maintenance burden, though it fits a feature-rich Symfony bundle.
The repository owner is an individual account rather than an organization, so the package has no demonstrated organizational backing to offset a thin maintainer base.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a concrete sign that maintenance has recently paused.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/lock Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
nesbot/carbon Version ^2.72 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.