Usable with caveats: this is a mature package with a long release history, but it has had no release in over a year and does not declare a source repository. The assessed release is also a release candidate, so verify that it fits your production requirements.
57%
Total Score
50
80
100
The package declares 18 runtime dependencies, which creates meaningful transitive maintenance surface for a core framework component. The list is consistent with the package's broad CMS functionality, so this is a manageable concern rather than a severe risk.
The package has existed for over 10 years with 353 releases, showing substantial maturity, but it has had no release in the last 12 months and the latest release is over a year old. This lowers confidence in current maintenance.
The assessed version is a release candidate, which is less suitable for production than a stable release. The package's latest version is stable and recent releases contain no prereleases, partially offsetting this concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.1 | — | — |
cocur/slugify Version ^2.3 | — | — |
doctrine/dbal Version ^2.5 | — | — |
mrclay/minify Version ^2.3 | — | — |
smarty/smarty Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.