The package includes tests, a clear README, an MIT declaration, and no install-time scripts. Its small repository footprint and absent security policy leave limited extra assurance.
60%
Total Score
50
88
75
The latest release was nearly 7 years ago, with no releases in the last 12 months. That indicates materially stale maintenance for a dependency, although the package has an established release history.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is strong evidence of stalled maintenance.
There were no new or closed issues or pull requests in the last month, while one issue and three pull requests remain open. This suggests little recent project activity.
Composer build tooling is present, but no security-scanning tooling was detected. That reduces assurance about ongoing dependency and code hygiene, though it is not severe on its own.
The repository has no security policy, leaving no published process for reporting or coordinating security issues. This is a transparency gap, but not evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ~3.0|^4.0 | — | — |
symfony/config Version ~3.0|^4.0 | — | — |
symfony/http-kernel Version ~3.0|^4.0 | — | — |
byscripts/static-entity Version ~2.0 | — | — |
symfony/http-foundation Version ~3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.