MIT licensing, tests, and release notes improve transparency. Install and update hooks plus 51 runtime dependencies add maintenance exposure.
58%
Total Score
75
50
92
50
The package declares 51 runtime dependencies, creating a broad maintenance surface and more transitive components to keep compatible. That is understandable for a full Symfony boilerplate but still increases upkeep exposure.
The package declares post-install and post-update Composer scripts, adding code execution during dependency operations. This is a maintenance and review concern, though the signal does not show that the scripts are harmful.
The package has had no releases in the last 12 months, despite 14 releases overall and a latest release in April 2025. This indicates materially slowed maintenance for a Symfony boilerplate.
The repository recorded no commits and no active maintainers in the last 3 months. That weakens evidence of ongoing maintenance, although the repository is not archived.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
league/csv Version ^9.9 | — | — |
symfony/uid Version 7.2.* | — | — |
doctrine/orm Version ^3.3 | — | — |
symfony/flex Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.