The repository has had no commits, issues, or pull-request merges in the last three months. Strong tests, release notes, licensing, and organization backing improve transparency, but the package has limited current maintenance evidence.
42%
Total Score
75
79
50
The registry marks the entire package as abandoned and points to algolia/search-bundle as its replacement. Package-level deprecation is a severe adoption risk even though this specific release is stable.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. A recent release partly offsets this, but the current maintenance signal is weak.
There were no new or closed issues and no merged pull requests in the last month, despite 18 open issues and 8 open pull requests. This suggests limited recent project response.
The linked repository name does not match the package name and its README does not mention this package. That mismatch raises uncertainty about whether the repository directly represents the published package.
The repository has no security policy file. This is a transparency gap for a package that integrates application data with an external search service.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^7.0 || ^8.0 | — | — |
symfony/serializer Version ^7.0 || ^8.0 | — | — |
doctrine/persistence Version ^2.1 || ^3.0 || ^4.0 | — | — |
doctrine/event-manager Version ^1.1 || ^2.0 | — | — |
symfony/property-access Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.