The license needs clarification, and the linked repository does not identify this package in its README. Organization ownership and no install scripts provide limited reassurance.
18%
Total Score
100
40
75
The package has had no release in more than nine years: all five releases were published in May 2017, with none in the last 12 months. This is strong evidence of abandonment for a dependency.
The repository is not formally archived, but it was last pushed in May 2017, matching the stale registry history. That lack of activity offers little practical maintenance assurance.
The manifest declares a Proprietary license while the repository license file is recognized as BSD-3-Clause. This mismatch needs clarification before adoption, even though a repository license exists.
The repository name does not match the package name and its README does not mention this package, so the source-package relationship is not clearly established. The organization owner is a partial compensating signal, but not enough to remove the concern.
The repository has no security policy. For an old, unmaintained dependency, the absence of a documented vulnerability-reporting path adds transparency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^2.7 || ^3.0 | — | — |
movingimage/vm6-api-bundle Version dev-master | — | — |
movingimage/data-provider-vm6 Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.