The MIT license, readable setup guide, and organization-backed repository provide useful transparency. Install-time scripts and no security tooling add operational risk.
12%
Total Score
50
50
50
Packagist marks the entire package as abandoned and names kunstmaan/cms-skeleton as its replacement. This is a direct warning against taking a new dependency on this package.
The last registry release was on April 18, 2019, and there were no releases in the last 12 months. The package has a long release history, but it is no longer receiving releases.
The repository had zero commits and zero active maintainers in the last three months. Together with the old latest release and archived status, this strongly indicates abandonment.
The linked repository is archived, with its last push on December 10, 2021. An archived source repository indicates the project is no longer maintained for ongoing dependency use.
The package runs post-install and post-update Composer scripts. These are common for a Symfony application skeleton but increase installation complexity and warrant extra review when adopting an abandoned package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version ^1.4 | — | — |
symfony/symfony Version ^3.4 | — | — |
ekino/newrelic-bundle Version ~1.3.2 | — | — |
kunstmaan/bundles-cms Version 5.2.4 | — | — |
symfony/monolog-bundle Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.