Usable with caveats: the package is licensed, documented, stable, and backed by a matching organization repository. However, its last release and repository push were in February 2017, with no recent commits or releases, so maintenance and compatibility risk are significant.
52%
Total Score
50
50
81
83
The package has only three releases and none in the last 12 months; its latest release was in February 2017, indicating a long period without published maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being in 2017 and creating substantial abandonment and compatibility risk.
The bundle has four runtime dependencies, including its related BenGorUser components and Symfony Security, which is a focused profile but creates compatibility dependence on an aging component family.
Composer build tooling is present, but no security scanning tools were detected; this is a modest process gap, partly outweighed by the repository's small and inspectable file tree.
The repository has no security policy, reducing transparency for reporting vulnerabilities or handling security issues, although the package has no observed dangerous workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bengor-user/user-bundle Version ^0.6 || ^0.7 || ^0.8 | — | — |
symfony/security-bundle Version ^2.8 || ^3.0 | — | — |
bengor-user/symfony-security-bridge Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.