The MIT license, clear README, and extensive repository tests provide useful transparency. Its install-time scripts and lack of security tooling add smaller concerns, but the long maintenance gap dominates adoption risk.
38%
Total Score
0
50
75
50
The package has had no release in roughly 10 years: its latest release was July 2016, with zero releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap and indicating no current maintenance capacity.
The package declares 11 runtime dependencies, including Symfony, JMS, Sensio, and FOSRest components tied to its Symfony 2 integration story. This creates substantial compatibility and maintenance risk for current projects.
The package runs post-install and post-update Composer scripts, increasing install-time behavior and maintenance surface compared with a package containing no lifecycle scripts.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing visibility into dependency and build risks, especially for an unmaintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.2.3 | — | — |
jms/serializer Version ~1.0 | — | — |
jms/di-extra-bundle Version ~1.4 | — | — |
symfony/twig-bundle Version ~2.3 | — | — |
jms/serializer-bundle Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.