This is a promising but very young package: it has only been published for 16 days, yet already has three stable releases, active repository commits, three active contributors, ten merged pull requests in the last month, comprehensive README/changelog/test coverage, and a matching repository. The package is not deprecated or archived, is MIT-licensed, and has no install-time lifecycle scripts. The main concerns are limited historical maturity, zero repository popularity, absent security scanning and security policy, and a workflow without explicitly declared top-level token permissions. These are meaningful transparency and hardening gaps, but the observed development activity and repository scaffolding make the package reasonably adoptable with normal review of its rapid-release history and dependency surface.
78%
Total Score
100
50
83
80
The package declares 17 runtime dependencies, including major Symfony, Doctrine, Twig, and UX components; this is a meaningful integration surface and increases upgrade compatibility considerations, but the dependencies are relevant to the documented bundle functionality.
Three releases in 16 days with a median interval of about 8 days show active iteration, but the short history leaves long-term maintenance unproven.
The repository has zero stars, forks, and watchers. This does not establish unfitness, especially for a new package, but provides no external adoption evidence.
Composer build tooling is present, but no security scanning tools were detected. The missing automated security layer is a hardening gap, although it is not by itself evidence of unsafe maintenance.
No repository security policy was found, reducing vulnerability-reporting transparency and maintainer guidance for consumers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^7.0 | — | — |
symfony/routing Version ^7.0 | — | — |
twig/html-extra Version ^3.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.