The bundle is well documented, tested, licensed, and backed by an organization. Its short release history, zero repository activity for three months, and entirely unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
62%
Total Score
0
71
50
The repository recorded zero commits and zero active maintainers during the last three months, which is a concrete sign that maintenance may have stalled after the initial release burst.
The package is only 209 days old with three releases, all published within roughly one day of each other; this shows initial activity but little evidence of a sustained release track record.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no independent evidence of adoption or community support.
The project uses Make and Composer build tooling, but no security-scanning tools were detected. This is a hygiene gap for a package with a substantial dependency surface.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.0 || ^8.0 | — | — |
symfony/string Version ^7.0 || ^8.0 | — | — |
symfony/console Version ^7.0 || ^8.0 | — | — |
symfony/routing Version ^7.0 || ^8.0 | — | — |
rumenx/php-sitemap Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.