This bundle is my standard starter for all my Symfony projects.
47%
Total Score
unhealthy
Risky: one release, stalled activity, and a source repository that does not clearly identify this package.
This package has had only one release, published about two years ago, with no releases in the last 12 months. That leaves little evidence of sustained maintenance or release responsiveness.
The linked repository name does not match the package name and its README does not mention the package. This makes package-to-source ownership unclear rather than merely reflecting a normal monorepo subpackage.
The package declares 53 runtime dependencies, spanning Symfony, Doctrine, EasyAdmin, Twig, and many other components. That broad dependency surface increases upgrade and compatibility burden for a package with only one release.
The package runs post-install and post-update Composer scripts, increasing the amount of code executed during dependency changes. This is a supply-chain and maintenance hygiene concern even though it is not a malware verdict.
Only one registry account has publish access. The source repository is owned by an individual account, so there is no provided organization backing to compensate for the thin publishing base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
doctrine/orm Version ^3.2 | — | — |
symfony/flex Version ^2 | — | — |
symfony/form Version 7.1.* | — | — |
symfony/intl Version 7.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.