The latest release is recent and includes tests, release notes, and a matching source repository. Maintenance is thin, with one recent contributor, no security policy, and unpinned workflow actions.
35%
Total Score
50
60
50
Packagist marks the entire package as abandoned and points users to jord-jd/symfony-password-exposed-bundle. This is a direct adoption risk even though the assessed release is recent.
The linked repository is owned by an individual account, not an organization. Combined with concentrated recent commits, this provides limited visible backing if the maintainer stops.
The package has only 3 releases since June 2019, with 2 releases in the last 12 months and a median interval of about 3.5 years. Recent activity helps, but the long historical gaps show limited release maturity.
All recent commits came from one contributor, giving the project a concentrated maintenance base. The repository owner is an individual rather than an organization, so there is no shown organizational handoff cushion.
The repository had 1 commit in the last 3 months from 1 active maintainer. That demonstrates recent activity but provides little evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.4 || ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/config Version ^4.4 || ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/validator Version ^4.4 || ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^4.4 || ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/translation Version ^4.4 || ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.