Its organization backing, tests, README, and long release history provide useful maintenance context. The repository has no security policy, and its name and README do not identify this package, which weakens transparency. The package remains active enough to use with caveats.
68%
Total Score
88
100
78
83
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete warning about current development momentum, partly offset by the recent push and ongoing registry releases.
The repository name does not match the package name and its README does not mention the package. Although subtree-split packaging can explain the structure, the missing identity link still reduces transparency.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little independent evidence of broad community adoption.
Composer is used as the build tool, which fits the PHP package. No security scanning tools were detected, leaving a modest repository hygiene gap.
No security policy was found in the repository. For a framework bundle, this weakens vulnerability-reporting transparency and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
enhavo/metadata Version ^0.15 | — | — |
enhavo/app-bundle Version ^0.15 | — | — |
behat/transliterator Version ^1.5 | — | — |
symfony-cmf/routing-bundle Version ^3.0 | — | — |
enhavo/doctrine-extension-bundle Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.