The package includes tests, documentation, and a matching MIT license. Its workflow uses five unpinned actions, and the repository has no security scanning, increasing maintenance and build-integrity concerns.
62%
Total Score
75
88
75
The package has 20 releases over roughly 10 years, but none in the last two years. The linked repository was pushed more recently and the assessed version has release notes, partly offsetting the stale registry cadence.
There were no commits or active maintainers in the last three months. This is a meaningful maintenance concern, although the repository is not archived and was pushed in December 2025.
Composer build tooling is present, but no security scanning tools were detected. For a security-token bundle, that missing security automation is a modest transparency and maintenance gap.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which matters for a package handling security tokens.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkout, or audit findings. However, all five action references are unpinned, leaving build inputs less reproducible and less resistant to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.7|^3.0 | — | — |
doctrine/common Version ^3.0 | — | — |
doctrine/doctrine-bundle Version ^2.0 | — | — |
symfony/framework-bundle Version ^4.4|^5.0|^6.0|^7.0 | — | — |
yokai/dependency-injection Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.