Documentation and repository tests are present, and the package has a clear MIT license. Its lack of releases and commits for roughly two years, combined with fully unpinned workflow actions, raises maintenance and build-reproducibility concerns.
58%
Total Score
83
100
83
50
The package has had no release in roughly two years and no releases in the last 12 months, despite four releases overall. This is a meaningful maintenance concern for a dependency, though the stable 1.0.3 version remains available.
There were no commits and no active maintainers in the last three months, consistent with the broader lack of releases and indicating a real risk of stalled maintenance.
The repository has only 2 stars, 1 fork, and no watchers. Popularity is supporting evidence rather than a verdict, but these low adoption signals provide little evidence of a broad maintenance community.
The repository uses Composer and Make, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence that the package is unfit.
No security policy is present in the repository, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.