Its broad set of 21 runtime dependencies increases upkeep risk for a setup bundle. The source could not be found through the repository lookup, leaving maintenance and provenance unverified.
12%
Total Score
50
17
Packagist marks the entire package as abandoned, with no replacement named. That is a severe adoption risk because continued maintenance is not indicated.
The latest release was in December 2016, with zero releases in the last 12 months despite the package being over 11 years old. This strongly indicates abandonment.
The bundle declares 21 runtime dependencies, creating substantial maintenance and compatibility exposure for a setup package, with no supplied evidence that this breadth is actively managed.
Version 0.7.0 is not a prerelease, but it remains below 1.0, so compatibility expectations are weaker; this is secondary to the abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
symfony/symfony Version 3.2.* | — | — |
twig/extensions Version ~1.0 | — | — |
fzaninotto/faker Version ~1.6.0 | — | — |
liip/imagine-bundle Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.