The package is small and has a simple runtime dependency profile. Its minimal documentation, absent security policy, and repository/package naming mismatch add transparency concerns alongside the long maintenance gap.
38%
Total Score
50
100
63
83
The package has had no release in more than six years, with zero releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security updates.
There were zero commits and zero active maintainers in the last three months, following a last repository push in April 2020. This materially raises abandonment and compatibility risk.
One registry maintainer is listed, which is a thin publishing base. The organization-backed repository provides some context, so this is a modest concern rather than a severe ownership risk.
There are two open issues and no issue or pull-request activity in the last month. The small counts are not decisive, but the lack of response is consistent with a dormant project.
The repository name does not match the package name and its README does not mention the package. Although naming differences can occur in bundles, the combined mismatch makes package provenance less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^2.7|^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.