This is a mature, licensed, non-deprecated package with a long release history, a stable current version, documented source, repository tests, and organization backing. The main concern is maintenance momentum: only two releases occurred in the last 12 months and the repository recorded no commits or active maintainers in the last three months, while repository security-policy and security-scanning coverage is absent. It remains a reasonable dependency for an existing Symfony-based application, but adopters should verify ongoing compatibility and support before making it a new foundational dependency.
72%
Total Score
75
50
83
90
Nine runtime dependencies create meaningful transitive maintenance exposure, including several tightly coupled Kunstmaan and Symfony components, though the profile is not unusually large for a framework bundle.
The package has existed for 5175 days with 208 releases, indicating substantial maturity, but only 2 releases in the last 12 months suggest a slower current cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a concrete sign of currently weak maintenance momentum despite the recent push and long release history.
There were no new or closed issues and no pull requests in the last month, with zero open pull requests; this provides little evidence of active community maintenance, although the open-issues count is unknown.
The repository has 19 stars and 4 forks, indicating a relatively small user and contributor footprint; this is supporting caution rather than a decisive concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-320282 kunstmaan/form-bundle is vulnerable to Arbitrary File Upload in versions 0.0.1 - 7.3.0. | 0.0.1 - 7.3.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
symfony/mailer Version ^6.4|^7.2 | — | — |
behat/transliterator Version ^1.3.0 | — | — |
symfony/css-selector Version ^6.4|^7.2 | — | — |
kunstmaan/node-bundle Version ^7.0 | — | — |
kunstmaan/admin-bundle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.