The lone registry maintainer and missing security policy provide little ongoing support or transparency. A documented README, changelog, and MIT declaration help consumers, but they do not offset the maintenance concerns.
12%
Total Score
25
40
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level abandonment is a severe adoption risk rather than a cosmetic metadata gap.
This package has only one release, published over 12 years ago, with no releases in the last 12 months. That leaves compatibility and maintenance concerns unresolved for a framework integration.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived state and showing no current maintenance capacity.
The linked repository is archived and was last pushed in March 2015, indicating that active development has ended for more than 11 years.
Only one account has registry publish access. The organization-owned repository provides some project backing, but the observed publishing base is still thin for a package already showing long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sonata-project/intl-bundle Version 2.2.* | — | — |
sonata-project/user-bundle Version 2.2.* | — | — |
sonata-project/admin-bundle Version 2.2.* | — | — |
sonata-project/media-bundle Version 2.2.* | — | — |
presta/composer-public-bundle Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.