The large dependency footprint and install-time scripts add maintenance and reproducibility work. Tests and documentation are present, but the project lacks a security policy and automated security scanning.
30%
Total Score
25
50
67
67
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This creates a serious adoption and redistribution constraint.
The package has had no release in nearly five years: all three releases occurred on October 26, 2021, with none in the last 12 months. That strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The release declares 41 runtime dependencies, including a broad Symfony application stack. That increases update and compatibility burden for a project with no recent maintenance activity.
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution and reproducibility concerns. The signal does not show that these scripts are malicious, but they increase operational risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
doctrine/orm Version ^2.10 | — | — |
symfony/flex Version ^1.3.1 | — | — |
symfony/form Version 5.3.* | — | — |
symfony/intl Version 5.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.