The repository is still active and backed by an organization, with tests, a changelog, and a clear README. Its last registry release was over two years ago, while recent repository activity is not reflected in release cadence; the missing security policy is another modest gap.
61%
Total Score
75
86
75
The package has 150 releases since 2016, but none in the last 12 months and its latest release was over two years ago. This weakens confidence that published fixes will arrive promptly.
There were no commits and no active maintainers in the preceding three months. The recent repository push helps, but the observed short-term activity remains thin.
The repository name does not exactly match the package name and its README does not mention the package. Organization backing and the matching bundle source tree reduce concern, but the linkage is less explicit than ideal.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0|^3.0 | — | — |
doctrine/orm Version ^2.5|^2.6 | — | — |
symfony/form Version ^3.0||^4.0||^5.0||^6.0 | — | — |
ns/flash-bundle Version ^1.0|^2.0|^3.0 | — | — |
symfony/routing Version ^3.0||^4.0||^5.0||^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.