Its MIT declaration and matching source repository provide basic transparency, while the repository is not archived. No security scanning and no visible test suite leave limited evidence of project care.
30%
Total Score
0
64
50
The package is nearly 10 years old, with 11 releases clustered in November 2016 and no releases in the last 12 months. This strongly indicates abandonment risk.
There were no commits and no active maintainers in the preceding three months. Combined with the old last push, this is strong evidence that maintenance has stopped.
The artifact includes a substantial README and this version has a GitHub release, but it contains no tests and its README explicitly warns that the bundle is bad and not working. Missing tests are normal packaging practice, so the warning is the material concern.
Composer is used for the build, but no security-scanning tools are configured. This is a transparency and maintenance gap, though it is less serious than the prolonged inactivity.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, but it is secondary to the package's lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nelmio/cors-bundle Version >=1.4 | — | — |
jms/serializer-bundle Version >=1.1 | — | — |
nelmio/api-doc-bundle Version ^2.13 | — | — |
sensio/generator-bundle Version >=3.0 | — | — |
friendsofsymfony/rest-bundle Version >=1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.