The package has no tests or security scanning, and its ten runtime dependencies add maintenance surface. MIT licensing, a usable README, and a repository that matches the package improve transparency, but do not offset the long inactivity.
42%
Total Score
0
50
75
75
This is the only release, published in January 2022, with no releases in the last 12 months. That leaves the package with strong abandonment risk despite the absence of registry deprecation.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's multi-year release gap. No provided activity signal compensates for this inactivity.
The package declares ten runtime dependencies, including Symfony, Doctrine, Twig, and a CKEditor bundle. This creates substantial compatibility and maintenance surface for an unmaintained 0.0.1 release.
Composer is used for builds, but no security scanning tools are present. This is a meaningful maintenance and transparency gap for a package handling framework, database, and mail integrations.
The repository has no security policy, leaving users without a documented vulnerability-reporting path. This adds a transparency concern, though it is less serious than the inactivity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
doctrine/orm Version ^2.8 | — | — |
symfony/form Version ^5 | — | — |
symfony/config Version ^5 | — | — |
symfony/mailer Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.