The package includes tests, a changelog, clear licensing, and a repository that matches its name and documentation. Maintenance evidence is weak, with no recent release or commit activity and no repository security policy or scanning; pin it only if its older Symfony compatibility remains suitable.
55%
Total Score
50
83
50
Only one registry account has publish access. A single maintainer increases continuity risk, especially alongside the lack of recent commit and release activity.
The package has had 6 releases, but its latest release was over 5 years ago and there were no releases in the last 12 months. This is meaningful evidence of stagnation for a dependency that may need framework compatibility updates.
The repository had no commits and no active maintainers during the last 3 months, consistent with the package's long release gap. That lowers confidence that compatibility or defects will be addressed.
Composer is used for builds, but no security-scanning tools were detected. The build tooling is appropriate, while the missing scanning adds a modest maintenance and assurance gap.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is less severe than an archived or deprecated project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
misd/linkify Version ^1.0 | — | — |
symfony/framework-bundle Version ^2.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.