The package has tests, a README, and a stable MIT declaration. Its release and repository activity stopped in November 2019, with no security policy or scanning in the repository.
43%
Total Score
50
75
75
The latest release was November 2019, with no releases in the last 12 months and only four releases over roughly 12 years. This is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving current maintenance capacity un demonstrated.
The repository name does not match the package name and its README does not mention this package, so the source-package relationship is not clearly documented. Organization backing provides some context but does not resolve that mismatch.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a maintenance and assurance gap, though it is not severe on its own.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This adds a moderate hygiene concern alongside the stale maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version >=2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.