The license, README, and matching repository make its purpose and contents clear. There has been no recent development, and the project has little adoption or security-process evidence; pinning this release creates a substantial abandonment risk.
42%
Total Score
50
79
83
The package has only two releases, both published within about one day, and none in the last four years and eight months. This strongly suggests the project is no longer maintained.
There were zero commits and zero active maintainers in the last three months. Combined with the repository's last push being over four years ago, this is a meaningful abandonment concern.
The repository has one star, zero forks, and two watchers, providing little evidence of an active user or contributor community. Popularity is supporting evidence, but it reinforces the maintenance concern.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a hygiene gap that matters more for a framework integration package.
Version 0.0.2 is not a stable major release, which indicates an early-stage API and adds compatibility risk. The absence of prereleases does not compensate for the long period without updates.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
doctrine/orm Version ^2.8 | — | — |
symfony/form Version ^5 | — | — |
symfony/config Version ^5 | — | — |
symfony/routing Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.