The single-owner project has no security policy, no security scanning, and very little visible community activity. Pin v2.1.7 only if its older Symfony and frontend dependencies remain compatible with your application.
38%
Total Score
0
67
75
The last release was December 11, 2020, nearly six years ago, and there have been no releases in the last 12 months. Although 26 releases show earlier development, the current release history indicates likely abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance to offset the stale release history.
The repository name does not match the package name and its README does not mention the package, which raises uncertainty about whether the linked repository is the package's maintained source.
The repository uses Composer for builds, which is appropriate, but no security-scanning tools were detected. The lack of scanning adds a modest maintenance and transparency concern.
No security policy was found, leaving no documented process for reporting or handling vulnerabilities. This is a meaningful transparency gap for a package with web and frontend integration code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
components/jquery Version ^3.1 | — | — |
components/jqueryui Version * | — | — |
twbs/bootstrap-sass Version ^3.3.0 | — | — |
mopa/bootstrap-bundle Version ^3.0 | — | — |
pinano/select2-bundle Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.