The package has clear documentation, tests, a changelog, and an MIT license, backed by an organization-owned repository. Its last release was about six years ago and recent commit activity is absent, so maintenance should be treated as limited.
58%
Total Score
75
100
88
83
The latest release was published about six years ago, with no releases in the last 12 months; this is a meaningful maintenance concern despite the package having 10 releases overall.
There were no commits and no active maintainers in the last three months, which reinforces the concern raised by the long gap since the latest release.
There was no recent issue or pull-request activity, and one pull request remains open; this offers little evidence of active maintenance.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a hygiene gap, not by itself a reason to reject the package.
The repository has no security policy, reducing transparency for vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^3.0|^4.2|^5.0 | — | — |
symfony/validator Version ^3.0|^4.2|^5.0 | — | — |
symfony/framework-bundle Version ^3.0|^4.0|^5.0 | — | — |
sensio/framework-extra-bundle Version ^3.0|^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.