Usable with caveats: it has clear documentation, tests, an MIT license, and a matching repository, but maintenance appears stalled since the latest release about 9 months ago. The immature 0.x version, zero recent commits, broad dependency footprint, and missing security policy warrant review before adopting it.
55%
Total Score
33
50
75
80
The repository recorded zero commits and zero active maintainers during the last 3 months, a concrete sign that maintenance has stalled and abandonment risk is elevated.
The package declares 30 runtime dependencies, including framework, database, administration, and related bundle components; this broad dependency surface increases upgrade and compatibility burden.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, providing limited backing capacity for a package with no recent commits.
There have been three releases over roughly 10 months, with a median interval of about 20 days, but no release is shown after December 2025 despite the later assessment date; that gap lowers confidence in active maintenance.
There are no open issues or pull requests and no activity in the last month; this is neutral for a small project, but it does not demonstrate an active support channel.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.