The package has tests, a README, and a declared MIT license, but its source repository has no recent maintenance or security policy. The repository also does not clearly identify the package, increasing uncertainty about ownership and support.
35%
Total Score
0
57
50
The last release was in March 2014, with no releases in the past 12 months and only three releases overall. This is strong evidence of abandonment for a package intended to integrate with a changing framework ecosystem.
The repository recorded zero commits and zero active maintainers in the past three months, and its last push was in August 2014. This indicates prolonged abandonment rather than merely a temporarily quiet project.
The artifact includes a README and tests, and the repository also has tests, which provide useful consumer and maintenance context. The README explicitly describes the bundle as early development and not ready for use, while the missing changelog is normal packaging practice and not material here.
The repository name does not match the package name and its README does not mention the package. Although a subpackage can legitimately use a differently named repository, these values leave the package-to-source relationship unclear.
The repository uses Composer, showing basic build tooling, but it has no security scanning tools. This is a modest transparency and maintenance gap, especially for an unmaintained authentication integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-uri Version ~2.0 | — | — |
symfony/security-bundle Version ~2.1 | — | — |
symfony/framework-bundle Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.