The release has a useful README, tests, changelog, and release notes, but it remains explicitly beta and its license metadata conflicts with the included MIT license. The linked repository also does not identify this package clearly, making ownership less transparent.
40%
Total Score
50
67
This is the package's only release, published in July 2015, with no releases in the last 12 months. That long gap is strong evidence of abandonment risk.
The repository has recorded zero commits and zero active maintainers in the last three months. Combined with the old one-release history, there is no observed maintenance capacity.
The artifact contains a recognized MIT license file, so the release is licensed, but the manifest declares BSD instead. This mismatch creates avoidable legal ambiguity.
The linked repository name does not match the package name and its README does not mention the package. Although name differences can occur in monorepos, the absence of any README mention makes package ownership less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version >=2.2.3,<2.5 | — | — |
jms/payment-core-bundle Version dev-master | — | — |
swiftmailer/swiftmailer Version 4.2.* | — | — |
symfony/framework-bundle Version ~2.5 | — | — |
stof/doctrine-extensions-bundle Version 1.x | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.