Usable with caveats: it has a long release history, a current stable release, clear licensing, and an active repository. Recent work is sparse and all commits in the last three months came from one contributor, so future maintenance capacity is the main concern.
68%
Total Score
63
100
94
75
One contributor made all commits during the last three months, giving the project a fragile short-term contributor base. The linked repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset that concentration.
Only one commit was recorded in the last three months, showing very light recent development even though it included the assessed release.
There are 41 open issues and four open pull requests, while no issues or pull requests were opened or closed in the last month. This indicates unresolved maintenance demand and limited recent responsiveness.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package used in web applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/form Version ~6.0|~7.0|~8.0 | — | — |
gregwar/captcha Version ^2.1 | — | — |
symfony/translation Version ~6.0|~7.0|~8.0 | — | — |
symfony/framework-bundle Version ~6.0|~7.0|~8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.