Clear documentation and broad automated tests support integration, but the project has shown little ongoing activity. Pinning dependencies and actions would reduce avoidable supply-chain exposure.
58%
Total Score
25
50
81
67
The repository had zero commits and zero active maintainers in the last 3 months, consistent with a project whose maintenance activity has stalled after its initial release.
The package declares 20 runtime dependencies, including several framework and project-specific bundles. This is a relatively broad dependency surface that increases upgrade and compatibility exposure.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is limited visible organizational backing.
This is a new package with only one release, first published about 10 months ago, so there is little release history to establish maintenance consistency.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
knplabs/knp-menu Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.