The MIT license, complete source tree, and organization backing improve transparency. No release has appeared for nearly 5 years, repository commits are inactive, and the repository does not identify this package in its README; its missing security policy adds concern.
38%
Total Score
50
50
83
The package has 18 releases but none in the last 12 months, and its latest release was published nearly 5 years ago. This long pause materially raises abandonment risk despite its earlier release history.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, providing no evidence of current maintenance capacity. This reinforces the stale release history.
The linked repository name does not match the package name and its README does not mention the package, so ownership of the published package is less transparent. The organization backing provides some compensation but does not resolve the mismatch.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these low adoption indicators provide little independent evidence of project maturity.
The repository has no security policy, leaving no documented channel or process for reporting security issues. This is a maintenance and transparency gap, though it is less serious than the inactive development signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ~2.3 | — | — |
symfony/form Version ^4.2|^5.0 | — | — |
symfony/config Version ^4.2|^5.0 | — | — |
doctrine/common Version * | — | — |
ecommit/util-bundle Version 2.5.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.