The package includes a usable README, a declared MIT license, and a small runtime dependency surface. It is not archived or deprecated, but its very old release and absent recent development make long-term maintenance uncertain.
42%
Total Score
100
75
75
Only two releases were published, with the latest on August 6, 2015 and none in the following 11 years. This is strong evidence of abandonment for a library dependency.
Composer is used as the build tool, but no security-scanning tooling is reported. That is a modest transparency and maintenance gap, though it is less significant than the prolonged inactivity.
The linked repository is not archived, which leaves maintenance possible. Its last push was March 4, 2017, so the non-archived status does not offset the long inactivity.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is secondary to the package's lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version 2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.