Its dependency footprint is modest, installation has no lifecycle scripts, and the package includes a README with a release history dating back to 2013. The two-person contributor base and lack of a security policy leave some maintenance and transparency risk.
83%
Total Score
83
100
94
75
Only two contributors were active in the last 3 months, and one made 5 of 6 commits, leaving a concentrated contributor base despite the organization backing.
Composer is used as the build tool, but no security scanning tools are present, leaving automated security hygiene less visible.
The repository has no security policy, so vulnerability reporting and disclosure expectations are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.7 || ^4.3 | — | — |
symfony/routing Version ^6.4 || ^7.4 || ^8.1 | — | — |
contao/core-bundle Version ^5.3 || ^6.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.4 || ^8.1 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.