The package includes tests, a clear MIT license, and a small runtime dependency set. Its organization-backed repository is not archived, but the project shows little evidence of current support and lacks a security policy.
38%
Total Score
83
100
71
50
The latest release was published in January 2018, and there have been no releases in the last 12 months despite the package being over 9 years old. This is strong evidence of abandonment risk, although the 28-release history shows it was previously established.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy for a small stable package, but alongside the old release it provides no evidence of ongoing community maintenance.
The repository has 1 star, 0 forks, and 0 watchers, indicating very limited adoption or visible community support. Popularity is supporting evidence rather than decisive, but it reinforces the maintenance concern.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a modest transparency gap, while Composer confirms a conventional package build setup.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less significant than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mindy/form-bundle Version >=4.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.