Risky to adopt for a new project: the package has had no release for over seven years and no recent repository activity. It is licensed, documented, tested, and not deprecated or archived, but its maintenance appears effectively stalled.
45%
Total Score
0
75
The latest release was published over seven years ago, with no releases in the last 12 months. This strongly increases abandonment and compatibility risk despite a previously regular release cadence.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. This is a substantial maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap, although it is secondary to the package's much older maintenance history.
The linked repository is not archived, which is a positive sign, but its last push was over seven years ago and does not offset the absence of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.14 | — | — |
symfony/form Version ~2.8|~3.0|~4.0 | — | — |
symfony/framework-bundle Version ~2.8|~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.