The MIT license, tests, release notes, and matching source repository improve transparency. Install-time scripts and absent security tooling add maintenance friction for a package with an aging dependency base.
40%
Total Score
0
79
50
The package has had 0 releases in the last 12 months, and its latest release was over 8 years ago. Earlier releases were frequent, but that history does not offset the prolonged current inactivity.
The repository had 0 commits and 0 active maintainers in the last 3 months. Combined with the old last push and release history, this is strong evidence that maintenance has stopped.
post-install-cmd and post-update-cmd scripts run during Composer operations, increasing installation complexity and the amount of package behavior that must be trusted. No provided signal shows these scripts are necessary or constrained.
Composer and Phing provide build tooling, but no security scanning tools are configured. For an application skeleton with runtime dependencies, this leaves a meaningful maintenance and vulnerability-monitoring gap.
The repository has no security policy. This weakens transparency about how vulnerabilities are reported and handled, especially for a package that includes application functionality.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phing/phing Version ^2.0 | — | — |
doctrine/orm Version ^2.5 | — | — |
symfony/symfony Version ^3.4 | — | — |
symfony/monolog-bundle Version ^3.0 | — | — |
doctrine/doctrine-bundle Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.