Its 35 runtime dependencies and four unpinned workflow actions increase maintenance and build-reproducibility costs. Tests, a substantial README, GitHub release notes, matching repository, and an MIT license provide useful support.
68%
Total Score
50
90
50
Thirty-five runtime dependencies create a broad maintenance and transitive-risk surface for a Symfony bundle, though the package's substantial integration scope partly explains the size.
The package is 507 days old with seven releases, but only one release in the last 12 months; this indicates noticeably slower maintenance than its early cadence.
The repository has no security policy, which reduces disclosed security-reporting guidance, although this is a transparency gap rather than evidence of an unsafe release.
Both workflows were analyzed with no detected dangerous findings, but all four action references are unpinned, reducing build reproducibility. One workflow also lacks a top-level permissions block, while another uses read-only permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/lock Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.