Usable with caveats: this is a mature, licensed Symfony bundle with a recent release, repository tests, and organization backing. Commit activity has been absent for three months, and the repository lacks a security policy and explicit workflow token permissions.
72%
Total Score
75
100
89
75
The package has been maintained since 2019 with 31 releases and a release about five months ago, but only one release appeared in the last 12 months, indicating a slower cadence.
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this because release activity is present, but the lack of current development activity remains a maintenance risk.
The repository has five open issues, with one new issue and no issues or pull requests closed in the last month; this is a modest maintenance concern but not evidence of abandonment by itself.
Composer build tooling is present, but no security scanning tool was detected, leaving a security-process gap in the repository.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
setono/tag-bag Version ^2.5 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
webmozart/assert Version ^1.11 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.