This is a generally healthy release to depend on: it has a stable major version, a long release history, a current release, an unarchived linked repository, a complete-looking artifact with tests, README, changelog, and license, and no install-time lifecycle scripts. The main concerns are the small repository audience, only one recent active contributor with all recent commits, no declared security policy or automated security scanning, and a publish workflow with top-level write permissions. These are meaningful supply-chain and continuity gaps, but they are partly offset by recent issue and pull-request resolution, clear package/repository alignment, and a well-structured tested source tree.
78%
Total Score
60
50
89
80
The package declares 21 runtime dependencies, including substantial Symfony, Doctrine, and FOSUserBundle components; this is reasonable for its framework-bundle role but increases compatibility and transitive-maintenance exposure.
Only one registry account, Azine IT Services AG, has publish access. The linked repository owner is an individual account rather than an organization, so there is limited observable publishing redundancy.
The repository is owned by the user account 'azine' rather than an organization, so the single-contributor and single-publisher findings are not visibly compensated by organization-level handoff capacity.
One contributor made all commits in the last three months, with a 100% share, creating a genuine continuity and abandonment risk; no organization backing is shown to compensate for this concentration.
Only one commit was recorded in the last three months, which shows some recent activity but a low maintenance cadence for a package with ongoing framework dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.14 | — | — |
doctrine/orm Version ^3.6 | — | — |
symfony/mime Version ^7.4 | — | — |
symfony/yaml Version ^7.4 | — | — |
symfony/config Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.