Tests, release notes, and organization backing provide useful maintenance evidence. Install-time hooks and the lack of security tooling add operational concerns alongside the long period without changes.
58%
Total Score
67
80
50
The package runs post-install and post-update Composer scripts, adding install-time behavior that consumers must account for. No provided signal shows that these hooks are unnecessary or compensated for.
The package has 64 releases since 2017, but none in the last 12 months and the latest release was nearly three years ago. Its historically regular cadence does not compensate for the current inactivity.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and indicating little current maintenance capacity.
There were no newly opened or closed issues and no merged pull requests in the last month, while 9 issues and 5 pull requests remain open. This reinforces the evidence of stalled maintenance.
The repository uses Make and Composer, which supports repeatable project work, but it reports no security-scanning tools. That is a modest transparency and maintenance gap for a dependency with application-facing code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ldap Version ^3.0|^4.0 | — | — |
symfony/config Version ^2.7|^3.0|^4.0 | — | — |
phpoffice/phpspreadsheet Version ^1.4 | — | — |
friendsofsymfony/user-bundle Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.