It is clearly licensed and includes consumer documentation plus tests. Install-time scripts and the prerelease status add operational friction for a new application.
12%
Total Score
0
50
50
The package has 89 historical releases, but its latest release was over 11 years ago and there were no releases in the last 12 months. That sustained absence outweighs its earlier release cadence.
There were zero commits and zero active maintainers in the last 3 months. Combined with the archived repository, this is strong evidence of abandonment rather than a temporary pause.
The linked repository is archived and was last pushed over 10 years ago, indicating the source is no longer maintained. The organization ownership does not compensate for the explicit archived status.
The package runs post-install and post-update Composer scripts, increasing installation and update complexity. No provided signal shows these scripts are unsafe, so this is a maintenance and operational caution rather than a severe risk.
The linked repository name does not match the package name and its README does not mention the package, so package-to-source ownership is not transparent. The mismatch may reflect a distribution repository, but the missing mention remains a caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ~2.2,>=2.2.3,<2.5 | — | — |
doctrine/dbal Version <2.5 | — | — |
symfony/symfony Version ~2.7@beta | — | — |
twig/extensions Version ~1.0 | — | — |
symfony/assetic-bundle Version ~2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.