Usable with caveats: this is a newly published package with clear ownership and documentation, but it has little operating history and limited visible project hygiene. Reassess it after sustained maintenance and testing activity.
61%
Total Score
75
50
79
50
The release declares 14 runtime dependencies and no development dependencies, creating a relatively broad dependency surface for a newly released package. This increases integration and maintenance exposure, although the signal alone does not show that the dependencies are unsafe.
The package is only 1 day old, with four releases in that time. This shows active initial publishing but provides too little history to establish dependable maintenance or release practices.
There are no commits recorded in the previous 3 months, but the project itself is only 1 day old and was pushed recently. This is insufficient history rather than evidence that established maintenance has collapsed.
The repository uses Composer, providing basic build/package tooling, but no security-scanning tool was detected. That is a modest transparency and maintenance gap for a package with multiple runtime dependencies.
No repository security policy was found. This is a transparency gap, though it is less concerning because the project is new and no other provided signal indicates an active security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version >=6.2 | — | — |
doctrine/orm Version >=2.14 | — | — |
symfony/routing Version >=6.2 | — | — |
wexample/php-helpers Version >=4.0.0 | — | — |
wexample/symfony-api Version >=5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.