Its MIT license, README, and lack of install scripts make the package straightforward to inspect and integrate. The package is deprecated, archived, and has had no releases or commits since 2013, so pinning it creates substantial abandonment risk.
12%
Total Score
0
100
42
100
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption concern because future maintenance and compatibility are not expected.
This package has only one release, published in February 2013, and none in the last 12 months. The long absence of releases strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its archived state. There is no observed recent activity to offset the maintenance risk.
The linked repository is archived and was last pushed in July 2015. An archived source project is no longer maintained and is a severe risk for a dependency.
The linked repository name does not match the package name and its README does not mention the package. Although the repository contents appear related, this mismatch reduces transparency about package ownership and provenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sonata-project/jquery-bundle Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.