The package contains no README and runs install-time scripts, limiting transparency for consumers. Its single release is over eight years old, and both the registry listing and source repository show abandonment.
8%
Total Score
30
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
This package has only one release, published over eight years ago, with no releases in the last 12 months. That strongly indicates abandonment rather than an actively maintained dependency.
The linked repository is archived and was last pushed over eight years ago, so it is unlikely to receive maintenance or fixes.
The package runs post-install and post-update scripts, adding execution during dependency operations. The signal does not show what those scripts do, so this is a review concern rather than proof of unsafe behavior.
The published artifact has no README, tests, changelog, or release notes. A missing README is a meaningful transparency gap for a Symfony application skeleton that consumers must understand and adapt.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lts Version ^4@dev | — | — |
symfony/yaml Version ^4.0 | — | — |
symfony/console Version ^4.0 | — | — |
rebolon/api-pack Version ^1.0.2 | — | — |
php-http/httplug-pack Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.