It has a clear MIT license, a usable README, and no install-time scripts. Its small two-package dependency set limits complexity, but these strengths do not offset the lack of recent activity.
35%
Total Score
33
100
75
75
The package has had no release in nearly 12 years: its latest release was published in October 2014, with none in the last 12 months. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No provided signal shows compensating maintenance activity.
One registry publishing maintainer gives the package a thin administrative base. This is a minor concern, while the much stronger evidence is the absence of recent release and commit activity.
There are no open issues or pull requests and no issue or pull-request activity in the last month. The clean tracker is not evidence of active maintenance given the repository's age.
The repository uses Composer, but no security scanning tools were detected. This is a hygiene gap rather than a severe risk, and the package's age makes the lack of current tooling more notable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version >=2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.