The package includes tests, release notes, a license, and a correctly linked repository. Its last registry release was about four years ago and the repository has had no commits in the last three months; all three workflow actions are unpinned, adding maintenance and build-integrity concerns.
62%
Total Score
50
50
81
83
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Eight runtime dependencies are substantial for a small Symfony bundle, increasing the maintenance surface, though the dependencies are relevant framework components rather than unexplained extras.
One registry publisher is consistent with the repository being owned by an individual, but it leaves a thin publishing base if that person becomes unavailable.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to compensate for the single-maintainer profile.
The package has made no release in about four years and has had no releases in the last 12 months, which is a meaningful maintenance concern for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
symfony/config Version ^5.4|^6.0 | — | — |
symfony/http-kernel Version ^5.4|^6.0 | — | — |
symfony/translation Version ^5.4|^6.0 | — | — |
symfony/twig-bundle Version ^5.4|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.