The package includes tests, a changelog, and a readable artifact, which help with basic review. Install-time scripts and 16 runtime dependencies add operational surface, while the single maintainer leaves little visible backup.
38%
Total Score
25
50
63
67
The package is about 5 years old but has only 2 releases, both published within roughly 28 minutes, with no releases in the last 12 months. This is strong evidence of abandonment risk.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has seen no recent maintenance for years.
The package declares 16 runtime dependencies, including framework, database, messaging, and storage components. This creates meaningful maintenance and compatibility surface, though the profile is understandable for a Symfony application.
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This limits transparency and may restrict adoption.
The package runs post-install and post-update Composer scripts, increasing installation-time behavior and review requirements. No provided signal shows that these scripts are unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.10 | — | — |
symfony/flex Version ^1.3.1 | — | — |
symfony/yaml Version 5.3.* | — | — |
symfony/dotenv Version 5.3.* | — | — |
symfony/console Version 5.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.