Usable with caveats: the package is clearly documented, tested, licensed, and linked to its matching repository, but it has had only one release and no commits for about one year. A single maintainer and limited repository security hygiene add maintenance risk.
58%
Total Score
38
100
83
80
There have been no commits and no active maintainers in the last three months, while the latest push was about one year ago. This is the strongest concern because it leaves maintenance and compatibility fixes unproven.
Only one registry account has publish access. That is a meaningful continuity risk for an independently owned package, even though access records do not prove actual maintenance activity.
The registry namespace and repository are owned by matching individual accounts, so the package has identifiable personal backing. It does not have organization-level redundancy to compensate for its single-maintainer structure.
This is the only release, published about one year ago, with no releases in the last 12 months. That limited history makes long-term maintenance less established.
There are no open issues or pull requests and no recent issue or pull request activity. The clean queue is positive, but the absence of activity offers little evidence of community engagement.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.21 | — | — |
symfony/yaml Version ^7.3 | — | — |
symfony/translation Version ^7.3 | — | — |
knplabs/knp-menu-bundle Version ^3.6 | — | — |
symfony/framework-bundle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.