The documentation is explicitly unfinished, and the project has no security policy or scanning. Its organization-backed repository and included package tests provide some traceability, but not enough for a dependable current dependency.
32%
Total Score
50
50
75
The package has made no release in more than 13 years: its latest release was in October 2012, with none in the last 12 months. This is strong evidence of abandonment for a dependency intended for ongoing use.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push having occurred more than 12 years ago. The long inactivity materially raises maintenance and compatibility risk.
A license file is present in both the artifact and repository, so the release is licensed. However, the manifest declares BSD while the detected license text is MIT, creating a potentially important licensing mismatch.
The artifact includes a README and tests, but the README calls the project a work in progress, says it is not documented, and leaves the user guide as TODO. The package is therefore traceable but poorly maintained for consumers.
The linked repository name does not match the package name and its README does not mention the package. Although name differences can be normal for subpackages, the lack of any README reference leaves ownership and source correspondence less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version >=2.1.0 | — | — |
symfony/framework-bundle Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.