The MIT license, detailed documentation, and release notes improve transparency. The organization-backed repository is not archived, but it has no security policy or security scanning.
38%
Total Score
50
79
50
The package has had no release for about 9 years, with zero releases in the last 12 months; its earlier 25-release history shows past activity but does not offset the prolonged gap.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and raising abandonment risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a security-sensitive user bundle.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^2.8 || ^3.0 | — | — |
bengor-user/user Version ^0.8 | — | — |
symfony/templating Version ^2.8 || ^3.0 | — | — |
symfony/translation Version ^2.8 || ^3.0 | — | — |
symfony/twig-bundle Version ^2.8 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.