The README, changelog, matching repository, and organizational backing improve transparency. Its 22 runtime dependencies, install-time scripts, license mismatch, and absent security policy add maintenance and review overhead.
34%
Total Score
50
50
70
50
The latest release was published in September 2014, with zero releases in the last 12 months and only six releases overall. This indicates a long-standing abandonment risk despite the package not being registry-deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's release inactivity and leaving little evidence of ongoing maintenance.
The package declares 22 runtime dependencies, including a large Symfony-era framework stack. This increases maintenance and compatibility exposure for a package whose own development has been inactive for years.
The release includes a license file and the repository also has one, but the manifest declares BSD while the artifact file is recognized as MIT. The package is licensed, yet the mismatch creates avoidable legal ambiguity.
The package runs post-install, post-root-package-install, and post-update-cmd scripts. These may be expected for a Symfony distribution, but they add install-time behavior that deserves review when maintenance evidence is weak.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ~2.2,>=2.2.3 | — | — |
symfony/symfony Version 2.5.* | — | — |
twig/extensions Version ~1.0 | — | — |
symfony/validator Version ~2.5 | — | — |
jms/di-extra-bundle Version ~1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.