The package is MIT-licensed and its source tree is small and coherent. It lacks consumer documentation and security tooling, with a single publisher, so ongoing support is uncertain.
42%
Total Score
33
50
72
83
Only two releases exist, both from September 2023, with no release in the past 12 months. This is strong evidence of stalled maintenance for a package developers would depend on.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Eight runtime dependencies, including Symfony components and related Ergnuor packages, create meaningful compatibility and maintenance surface for an early, inactive bundle.
Only one account has registry publish access. That is a thin publisher base and leaves little redundancy if the maintainer stops supporting the package.
The package and repository are owned by the same individual account rather than an organization, so there is no visible organizational backing to offset the single-maintainer risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ergnuor/api Version ^0.2.0 | — | — |
symfony/cache Version ^6.3 | — | — |
symfony/config Version ^6.3 | — | — |
symfony/http-kernel Version ^6.3 | — | — |
symfony/framework-bundle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.