It has a clear MIT license, tests, a README, and a small, coherent package tree. The repository has had no commits or releases for about five years and lacks security scanning, so maintenance confidence is low.
28%
Total Score
0
64
75
The package borrows the identity of the much more established symfony/debug-bundle, with borrows_lookalike_identity true and no self-described fork or integration. This creates a serious risk that consumers intended to install the other package.
The package has only one release, published about five years and nine months ago, with no releases in the last 12 months. That is strong evidence of an immature or abandoned release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of newer releases. The package is not archived, but there is no observed recent maintenance to offset the age.
The repository has zero stars and zero forks, with only six watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of an active user or contributor community.
The repository has no security policy and no documented security process. This is a transparency gap, though it is less serious than the stale release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.1 | — | — |
mgid/pagination Version ^1.0 | — | — |
symfony/framework-bundle Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.