The bundle has 32 runtime dependencies and all four workflow actions are unpinned, increasing maintenance and build-reproducibility concerns. A clear MIT license, tests, documentation, and a repository that matches the package provide useful support, but there is no security policy.
58%
Total Score
50
50
75
67
The package declares 32 runtime dependencies for a Symfony integration bundle, creating a broad compatibility and maintenance surface for consumers.
The package and repository share the same individual owner, which is consistent ownership but does not provide organizational backing or a broader maintenance base.
The package has only one release, published about 9 months ago, so there is little evidence of an established release process or sustained maintenance.
There is one open issue but no issues or pull requests were opened or closed in the last month, offering little evidence of active community maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal for this new package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
psr/cache Version ^2.0 || ^3.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.