Risky to adopt: this package has had no release or repository activity since July 2019, and its published artifact contains only composer.json. The install-time scripts and lack of security policy add operational concerns despite the MIT license and a non-deprecated repository.
28%
Total Score
25
64
50
The artifact and linked repository each contain only composer.json, leaving no implementation, documentation, or supporting project files visible for review. This is a substantial transparency concern for a Symfony skeleton package.
The package has only two releases, both published in July 2019, with no releases in the last 12 months; this is strong evidence of abandonment for a dependency released nearly seven years ago.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in July 2019 and indicating no current maintenance capacity.
The package runs post-install and post-update scripts, increasing installation complexity and the consequences of depending on an old, minimally documented package.
The package is backed by a personal user account rather than an organization, and the available activity shows no recent maintenance. There is no organizational backing to compensate for the inactive maintainer profile.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^1.1 | — | — |
symfony/framework-bundle Version 4.3.* | — | — |
deltachaos/example-529-plugin Version ~0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.