Usable with caveats: this is a very new package with only two releases and one recent contributor commit, so its maintenance track record is unproven. The repository is active, organization-backed, correctly linked, and the package has a README and no install-time scripts.
62%
Total Score
67
50
86
88
The package declares eight runtime dependencies, including several related Wexample packages and Doctrine/Symfony components. This creates meaningful coupling, but the profile is consistent with a Symfony platform bundle rather than inherently unhealthy.
The package is only 5 days old with two releases, so there is too little history to establish mature maintenance or long-term stability.
All recorded recent commits came from a single contributor. Organization backing provides some handoff potential, but no second active contributor is shown.
Only one commit from one active maintainer was recorded in the last 3 months. The recent activity is encouraging, but the very small amount of activity leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and assurance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version >=6.2 | — | — |
doctrine/orm Version ^3.0 | — | — |
wexample/symfony-api Version >=5.0.0 | — | — |
wexample/symfony-user Version >=1.0.0 | — | — |
wexample/php-pseudocode Version >=1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.