Documentation and licensing are solid, and the source is substantial. Install scripts, a missing security policy, and no automated security scanning add operational risk, while maintenance is concentrated in one contributor.
68%
Total Score
100
50
81
75
The bundle declares 20 runtime dependencies, a relatively broad dependency surface that increases upgrade and compatibility burden, though its substantial admin functionality partly explains it.
The package runs post-install and post-update Composer scripts, adding execution during dependency operations and warranting review before adoption.
Although the project has 110 releases since June 2019 and the latest was about 5 months ago, only one release appeared in the last 12 months despite a historical median interval of about 5 days.
Composer build tooling is present, but no security scanning tools were detected, leaving a notable gap in ongoing dependency and source checks.
The repository has no security policy, so the process for reporting and coordinating vulnerability fixes is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
symfony/flex Version ^1|^2 | — | — |
symfony/form Version ^7.0 || ^8.0 | — | — |
symfony/asset Version ^7.0 || ^8.0 | — | — |
symfony/mailer Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.