This is a mature, actively published Symfony CMS package with a long history, 179 releases, stable versioning, an unarchived organization-backed repository, substantial documentation and tests, licensing, security tooling, and safe workflow patterns. The main adoption risks are that only one contributor made all 26 commits in the last three months, issue activity has stalled despite 96 open issues, and the package has a large runtime dependency surface; these suggest maintenance concentration and operational complexity, but do not outweigh the evidence of current repository activity and established project structure.
78%
Total Score
80
50
94
90
The package declares 60 runtime dependencies, including broad Symfony, Doctrine, and CMS integrations; this is substantial integration complexity, although it is consistent with a full-featured CMS rather than an unexplained minimal package.
The package has existed for 4270 days and has 179 releases, but only 2 releases occurred in the last 12 months; the long history is strong maturity evidence while the recent release cadence warrants some caution.
One contributor made all 26 commits in the last 3 months, creating a genuine continuity risk. Organization backing provides some ability to hand off maintenance, but no second active contributor is shown by this signal.
There are 96 open issues and 24 open pull requests, with no new or closed issues in the last month, although 6 pull requests were merged; the backlog and stalled issue movement are a maintenance concern but not evidence of complete abandonment.
All 4 workflows lack top-level token permissions declarations. No workflow has top-level write permissions, but explicitly constraining permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.6 | — | — |
doctrine/orm Version ^2.13 | — | — |
symfony/form Version ^6.4|^7.2 | — | — |
symfony/mime Version ^6.4|^7.2 | — | — |
symfony/yaml Version ^6.4|^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.