The package includes tests, a clear README, a matching MIT license, and no install-time scripts. Its modest repository adoption and limited security tooling provide less reassurance for a security-related bundle.
43%
Total Score
33
100
75
75
The latest release was published about eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package used in authentication infrastructure.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates no current maintenance capacity.
The repository is owned by an individual user rather than an organization. That does not imply poor quality, but it provides less visible backing when current activity is absent.
There are open issues and pull requests, but none were created, closed, or merged in the last month. This supports the broader evidence of inactivity.
Composer and Phing provide build tooling, but no security-scanning tools were detected. That is a hygiene gap for an authentication-related package, though it is less severe than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ~2.2 | — | — |
symfony/security-bundle Version ~2.3|~3.0 | — | — |
symfony/framework-bundle Version ~2.3|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.