The MIT license, organization ownership, and substantial compiled artifact provide useful transparency and support. The package lacks a consumer README and repository security tooling, leaving documentation and maintenance practices weaker than ideal.
60%
Total Score
75
100
79
83
The package contains no README, which is a meaningful documentation gap for a Symfony integration that consumers must configure, while the absence of tests and a changelog in the artifact is normal packaging practice.
The package has made no registry release in the last 12 months, and its latest release was about 19 months ago. Its earlier 561 releases show a strong historical cadence but do not offset the current inactivity entirely.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the repository not being archived.
No build tools or security scanning tools were detected, and security scanning is explicitly absent. This is a hygiene weakness, but it is not enough on its own to indicate abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for a package intended for application integration.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
symfony/config Version ^6.4 || ^7.1 | — | — |
survos/installer Version ^1.5 || ^2.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.1 | — | — |
symfony/property-access Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.