Usable with caveats: it has a stable release, a clear license, tests, and an active unarchived repository, but maintenance evidence is weak. No commits or active maintainers were recorded in the last three months, and the repository does not clearly identify this package in its name or README.
62%
Total Score
50
88
50
Only one registry publishing account is listed, which creates a thin operational base. The matching user-owned repository provides some backing, but not the resilience of a broader maintainer team.
No commits and no active maintainers were recorded in the last three months. This weakens evidence of ongoing maintenance, even though a recent package release exists.
The repository name does not match the package name and its README does not mention the package. This raises concern that the linked source may not clearly belong to the published package.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself severe.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear for a package that handles email and user data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.6|^3.0 | — | — |
symfony/config Version ^5.4|^6.4|^7.4|^8.0 | — | — |
twig/intl-extra Version ^2.0|^3.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
twig/extra-bundle Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.