The package has tests, a readable README, and a substantial source tree. Organization backing and an unarchived repository help, but missing security documentation and install-time scripts reduce transparency.
48%
Total Score
50
50
71
50
The package has 182 releases and a rapid historical cadence, but its latest release was about four years ago and it has had no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly four-year gap since the last push. This materially increases abandonment risk.
The package declares 24 runtime dependencies, including several framework, database, and UI-related components. That broad dependency surface increases upgrade and compatibility burden for an already inactive release.
The package declares post-install and post-update scripts. These can be legitimate for Composer packages, but they add installation complexity and deserve extra scrutiny when maintenance is inactive.
Composer and Phing build tooling are present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, especially for a package with many dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fi/osbundle Version ~2.0 | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/form Version 3.4.* | — | — |
symfony/lock Version 3.4.* | — | — |
symfony/yaml Version 3.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.