The package includes an MIT license, a README, tests, and no install-time scripts, while its repository matches the package and is organization-backed. The available evidence shows no current security policy or scanning and little sign of ongoing maintenance.
45%
Total Score
50
70
75
The latest release was published in September 2019, and there were no releases in the following 12 months; this indicates a maintenance gap of about seven years for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance to offset the stale release history.
Composer is used for builds, but no security scanning tools are present; this is a modest hygiene gap rather than evidence that the release is unsafe.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that integrates with Elasticsearch and Symfony.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
symfony/form Version ~2.7|~3.0 | — | — |
symfony/asset Version ~2.7|~3.0 | — | — |
ruflin/elastica Version 3.2.* | — | — |
symfony/console Version ~2.7|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.