The MIT license, readable documentation, small dependency surface, and absence of install scripts make the release straightforward to inspect and integrate. Its organization-backed repository is still available, but the package has little evidence of current security or maintenance practice. Pin this exact version rather than expecting future fixes.
42%
Total Score
50
100
75
75
The latest release was published in March 2019, with no releases in the last 12 months; this is strong evidence of abandonment for a dependency. The five-release history and stable version provide some maturity but do not offset the long gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history's prolonged inactivity. This materially raises the risk that defects or compatibility issues will go unaddressed.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that the repository belongs to this release. This weakens source transparency, although the repository is organization-owned.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap and does not by itself show that the release is unsafe.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities. The absence is a transparency gap, though it is less serious than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^3.4||^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.