Usable with caveats: it has frequent recent releases, active repository work, clear licensing, and matching source code. Dependence rests largely on one contributor, with no security policy or scanning and incomplete workflow permission declarations.
68%
Total Score
70
100
88
80
Only one registry account can publish releases, which creates continuity risk for a user-owned project even though repository activity is current.
The registry namespace and repository belong to the same individual user, confirming project ownership but offering no organizational maintenance redundancy.
One contributor made all four commits in the last 3 months, leaving the project highly dependent on a single person and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and maintenance gap for dependency security.
The repository has no security policy, so users lack documented guidance for reporting vulnerabilities or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.14|^3.0 | — | — |
symfony/cache Version ^6.4|^7.0|^8.0 | — | — |
symfony/config Version ^6.4|^7.0|^8.0 | — | — |
symfony/console Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-client Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.