The release includes a substantial test suite, clear documentation, a matching MIT license, and no install-time scripts. Its broad runtime dependency set and lack of repository security tooling add maintenance overhead, while the workflow references are not pinned.
65%
Total Score
50
50
86
75
The package declares 38 runtime dependencies, including substantial Symfony, Doctrine, and related bundle integrations. This broad dependency surface increases compatibility and maintenance overhead.
The repository recorded zero commits and zero active maintainers over the last three months. With the latest release about nine months ago, this indicates a meaningful recent maintenance slowdown.
Composer build tooling is present, but no security scanning tool is configured. That leaves a repository-level transparency and maintenance gap.
The repository has no security policy. This weakens the project's documented process for handling vulnerabilities, although it does not by itself show an active security issue.
Version 0.2.0 is not a prerelease, but it is still before a stable 1.0 major release, so API maturity may be limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.