The package includes tests, release notes, and an MIT declaration. Its repository has no security policy or scanning, and the source name does not match the package name.
42%
Total Score
0
63
50
The package has had no release in more than six years, despite five releases clustered in April 2020. This is strong evidence of abandonment risk for a framework bundle.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and providing no evidence of current maintenance.
The linked repository name does not match the package name, and no README mention was observed. That makes package-to-source ownership less transparent, although a subpackage or renamed repository could explain it.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^1.3.1 | — | — |
symfony/form Version 5.0.* | — | — |
symfony/intl Version 5.0.* | — | — |
symfony/yaml Version 5.0.* | — | — |
symfony/asset Version 5.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.