The package has no tests or security scanning, and its repository does not clearly identify the package. It is licensed and has no install-time scripts, but the maintenance record is too stale for a dependable integration.
32%
Total Score
0
50
75
There has been only one release, published about 13 years ago, with no releases in the last 12 months. This is strong evidence of abandonment rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push in 2017, this indicates prolonged inactivity.
The artifact includes a short README, while the absence of tests and a changelog is normal packaging practice and is not itself a health gap. The README offers only minimal consumer guidance.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked source repository is maintained specifically for this package.
Composer is used for the build, but no security scanning tools are configured. For an old integration bundle, this leaves dependency and source issues less likely to be detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rohea/openx-api-client Version * | — | — |
symfony/framework-bundle Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.