A README, tests, and Composer build make the small codebase understandable. One registry maintainer and no security policy leave limited resilience, despite organization ownership and a clean package structure.
38%
Total Score
25
75
75
The package has only 3 releases, all concentrated in 2016, with no release in roughly 10 years. This is strong evidence of abandonment risk for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with its last push being roughly 9 years ago. The lack of recent work materially lowers maintenance confidence.
Only one account has registry publish access, which limits publishing resilience. Organization ownership provides some compensating project backing, so this is a moderate concern rather than a severe one.
Composer is used for the build, which is appropriate for a Packagist package, but no security scanning tools are present. This is a modest supply-chain hygiene gap rather than evidence of a severe problem.
The linked repository has no security policy. This is a transparency and incident-response gap, especially for a package handling customer support data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ~2.1 | — | — |
gedmo/doctrine-extensions Version ~2.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.