It has a clear MIT license, tests, and organization backing, while limited adoption and no security policy reduce confidence. Pin v1.1.1 only if its older Symfony integration fits your application.
62%
Total Score
100
69
50
The latest of only three releases was published about six years ago, with no releases in the last 12 months. This indicates likely dormant maintenance and raises compatibility risk for current projects.
The repository has only 2 stars, 1 fork, and 5 watchers, so there is little visible community adoption to provide independent maintenance support. Popularity is supporting evidence, not decisive on its own.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository is not archived, but its last push was about six years ago, consistent with the stale release history. The non-archived status prevents this from being a stronger abandonment signal.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The small, dormant project profile provides no compensating security process in the collected signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version >=2.4 | — | — |
cocur/slugify Version >=3.1 | — | — |
sidus/base-bundle Version ~1.0 | — | — |
symfony/framework-bundle Version ~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.