The proprietary license limits reuse, while install-time scripts and no security policy add avoidable dependency risk. A documented package and matching README provide some transparency, but the maintenance outlook remains weak.
42%
Total Score
25
50
75
50
Only two releases exist, with the latest published in July 2018 and none in the last 12 months; this is strong evidence of long-term abandonment risk.
The repository had zero commits and zero active maintainers during the last three months, reinforcing the package's abandonment risk despite its non-archived status.
The package declares 26 runtime dependencies, creating a broad maintenance and transitive-risk surface for a small, apparently inactive project.
The manifest declares a proprietary license and no license file was found, which limits safe reuse and transparency for an open-source dependency.
post-install-cmd and post-update-cmd run during dependency operations, increasing supply-chain exposure compared with a package without install-time execution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lts Version ^4@dev | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/form Version ^4.0 | — | — |
symfony/ldap Version ^4.0 | — | — |
symfony/yaml Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.