The AGPL-3.0 declaration and organization backing make its provenance clear. The repository is small and has no security scanning, while the release and commit history are stale, with no tests or consumer README.
38%
Total Score
50
69
83
The package has 22 releases since December 2016, but none in the last 12 months; the latest release was in March 2021, indicating prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history and elevated abandonment risk.
The published artifact has no README, and the repository also reports no tests. Missing tests are normal packaging practice, but the absent consumer documentation is a minor transparency gap for a Symfony bundle.
The repository has zero stars and forks and only two watchers, providing little supporting evidence of active community use. Popularity is supporting evidence, so this reinforces but does not determine the abandonment concern.
Composer is used for the build, but no security-scanning tooling is present. This is a hygiene gap that adds modest maintenance risk, though it is not evidence of a security issue by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.7 | — | — |
swp/common Version ^2.0 | — | — |
swp/menu-bundle Version ^2.0 | — | — |
symfony/routing Version ^4.2 | — | — |
symfony/stopwatch Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.