Documentation and licensing are clear, and the runtime dependency set is modest. The project has no security policy, while the linked repository does not identify this package in its name or README.
55%
Total Score
67
100
75
75
The package has had no releases in the last 12 months, despite seven releases overall and a short historical median interval of about 8 days. This is a meaningful maintenance concern for a young package.
The repository recorded zero commits and zero active maintainers in the last three months. That is direct evidence of currently inactive development.
There were no new or closed issues or pull requests in the last month, while one issue and one pull request remain open. This supports a cautious view of project responsiveness.
The repository name does not match the package name and its README does not mention the package. That leaves uncertainty about whether the linked repository is the package's dedicated source.
Composer is used for builds, but no security-scanning tool is reported. The missing scanning is a modest transparency and hygiene gap, not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^5.4 | — | — |
craue/formflow-bundle Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.