Usable with caveats: the release is licensed, tested, documented, non-deprecated, and backed by an organization. However, registry releases have stopped for over a year and recent repository activity is absent, while the linked repository does not identify this package in its README.
68%
Total Score
67
100
78
75
The package has 12 releases over roughly nine years, but none in the last 12 months; the latest registry release was over a year ago. This is a maintenance concern, though the repository was pushed recently.
The repository recorded no commits and no active maintainers in the last three months, which is direct evidence of currently stalled development.
There are seven open issues but no new or closed issues and no pull-request activity in the last month, indicating limited current community or maintainer interaction.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent and the package may not be clearly identified by its source repository.
The repository has only one star and two forks, indicating limited adoption. Popularity is supporting evidence rather than decisive, and the organization backing and project structure partly compensate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.10 | — | — |
symfony/security Version ^4.4.10|^5.0 | — | — |
symfony/framework-bundle Version ^4.4.10|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.