The MIT license, repository tests, and release notes provide useful transparency. Its small user-owned project has no security policy, leaving little formal support if framework compatibility breaks.
42%
Total Score
25
79
50
The package has 16 releases since July 2014, but none in the last 12 months; its latest registry release was in May 2016, indicating prolonged abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap and weak maintenance outlook.
There were no new or closed issues in the last month and one open pull request, providing no evidence of active issue handling or ongoing development.
Composer is used for the build, but no security scanning tool was detected, leaving an avoidable maintenance and vulnerability-monitoring gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities; the otherwise transparent source repository does not compensate for that operational gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.15|~2.0 | — | — |
symfony/yaml Version ~2.3|~3.0 | — | — |
symfony/finder Version ~2.3|~3.0 | — | — |
symfony/twig-bundle Version ~2.3|~3.0 | — | — |
symfony/framework-bundle Version ~2.3|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.