The package has a clear README, tests, and a matching organization-owned repository. Its MIT license file is present, but the registry's proprietary declaration and absent security policy reduce transparency.
42%
Total Score
75
81
75
An MIT license file is present in both the artifact and repository, but the manifest declares the package as proprietary; that mismatch reduces licensing transparency.
The latest release was published in March 2020, and there were no releases in the following 12 months; this is a substantial maintenance and abandonment concern despite eight historical releases.
There were zero commits and zero active maintainers during the last three months, consistent with more than six years without repository updates and indicating serious abandonment risk.
Composer is used for builds, but no security scanning tools are configured; this is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; the long maintenance gap makes this omission more consequential.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/data-fixtures Version ^1.3 | — | — |
hautelook/alice-bundle Version ^2.0 | — | — |
symfony/phpunit-bridge Version ^4.3 | — | — |
symfony/framework-bundle Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.