Documentation, licensing, and a recorded release note support adoption, while the small user base limits fallback options. Pin this version only if its old PHP and Symfony requirements remain compatible with your project.
42%
Total Score
0
81
75
The package has had no release in about 9 years and none in the last 12 months, despite six releases overall. This is strong evidence of abandonment risk for a maintained dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No provided signal shows compensating recent maintenance.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a secondary concern beside the much larger maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^2.8 || ^3.0 | — | — |
bengor-user/user Version ^0.6 || ^0.7 || ^0.8 | — | — |
symfony/translation Version ^2.8 || ^3.0 | — | — |
symfony/twig-bridge Version ^2.8 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.