The repository remains open and well-documented, with tests, a changelog, and an active organization behind it. Workflow permissions are read-only, but all 13 external actions are unpinned and the project has no security policy.
62%
Total Score
67
88
50
Only two releases exist, and the latest was published nearly three years ago with no releases in the last 12 months. This is a meaningful maintenance concern for a dependency, despite the repository still being available.
There were no commits and no active maintainers in the last three months. Combined with the long gap between releases, this leaves maintenance responsiveness uncertain.
There are three open issues, but no new or closed issues or pull requests in the last month. This is a small supporting sign of limited recent activity rather than evidence of abandonment by itself.
The repository uses Composer and Make, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not a severe risk on its own.
No security policy was found in the repository. This weakens the project's documented process for handling vulnerabilities, though the package otherwise has tests and clear project documentation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.11 | — | — |
symfony/form Version ^5.4 || ^6.0 | — | — |
symfony/intl Version ^5.4 || ^6.0 | — | — |
symfony/asset Version ^5.4 || ^6.0 | — | — |
symfony/string Version ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.