The MIT license, included documentation, and small dependency set make the package straightforward to evaluate and integrate. Releases stopped about 11 years ago, repository commits stopped over 10 years ago, and no security policy is provided, leaving substantial maintenance risk.
38%
Total Score
0
100
61
83
The latest release was about 11 years ago, with no releases in the past 12 months. That strongly suggests abandonment risk for a framework integration package.
There were no commits and no active maintainers in the past three months, consistent with the repository having been inactive for over 10 years. This is the strongest ongoing-maintenance concern.
The repository name matches the package, reducing concern that it belongs to another project, but the README does not mention the package name. That weakens repository-to-package transparency somewhat.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a strong user or contributor community.
Composer build tooling is present, but no security-scanning tools are reported. This is a modest hygiene gap rather than evidence of unsafe behavior by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ~2.6 | — | — |
friendsofsymfony/jsrouting-bundle Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.