The package is well documented, tested, licensed, and has a current release with active organizational ownership. Recent repository work is sparse and concentrated in one contributor, while workflow dependencies are all unpinned and no security policy or scanning is reported.
70%
Total Score
63
100
94
75
All one recent commit came from a single contributor, creating concentrated maintenance capacity. Organization ownership provides some ability to hand off maintenance, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months, showing modest recent maintenance activity. This is partly offset by the recent release and repository push, but it still limits confidence in sustained maintenance.
There were no new or closed issues or pull requests in the last month, despite open issues and pull requests, indicating limited recent project interaction.
Composer and Box provide build tooling, but no security scanning tool is reported, leaving a modest transparency and detection gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 || ^4.0 | — | — |
fakerphp/faker Version ^1.14 | — | — |
symfony/console Version ^4.0 || ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
doctrine/event-manager Version ^1.0 || ^2.0 | — | — |
symfony/service-contracts Version ^2.1.2 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.