It has a license, tests, and a repository that clearly matches the package, providing basic transparency. The repository has no security policy, leaving vulnerability reporting and response expectations unclear.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that the release should not be adopted for new dependencies.
The latest release was published about 10 years and 11 months ago, with no releases in the last 12 months. The long release gap strongly indicates that the package is obsolete.
The repository recorded no commits and had no active maintainers in the last three months. Combined with the archived state, this confirms there is no current maintenance capacity.
The linked repository is archived and was last pushed in October 2015, indicating the source project is no longer maintained. This is a severe abandonment risk for a security-sensitive login bundle.
No security policy was found in the repository. For an authentication bundle, this is a meaningful transparency gap because reporting and response procedures are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version >=2.3 | — | — |
acts/social-api-bundle Version 0.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.