58%
Total Score
caution
No releases for over three years and no recent commits outweigh the package's documentation and organization backing.
The artifact includes six license files and detects MIT text, but the manifest declares a proprietary license. That mismatch makes the terms less clear to consumers.
The package has had no releases in the last 12 months, and its latest release was in December 2022, over three years ago. This is a substantial maintenance concern despite 16 releases overall.
There were zero commits and zero active maintainers in the last three months. Combined with the long release gap, this indicates weak current maintenance capacity.
There were no new or closed issues and no merged pull requests in the last month, with one pull request open. This is consistent with limited recent project activity.
Composer and Phing are used for builds, but no security scanning tools were detected. The missing scanning is a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/twig-bundle Version ^4.0|^5.0 | — | — |
knplabs/knp-menu-bundle Version ^2.1|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.