The small codebase includes a usable README, a declared MIT license, and no install-time scripts. Its repository is not archived, though the package-to-repository naming mismatch makes ownership less transparent.
58%
Total Score
50
81
75
The package has only one release, published about 10 months ago, so there is little evidence of an established release track or sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, leaving ongoing maintenance capacity uncertain.
The repository name does not match the package name and its README does not mention the package, making it harder to verify that the repository is the intended source.
Composer is used for the build, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.