The package is clearly licensed, has a matching repository, and avoids install-time scripts. Its small user-owned project has no tests or security policy, while maintenance stopped after the initial release, leaving longer-term support uncertain.
58%
Total Score
50
83
75
This package has only one release, v0.9.0, published 488 days ago, with no releases in the last 12 months. That is meaningful evidence of limited maintenance for a pre-1.0 library.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the lack of follow-up releases. This raises support and abandonment risk, though the repository is not archived.
The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of external adoption or a broader support community. Popularity is only supporting evidence, so this remains a moderate concern rather than a verdict.
The linked repository has no security policy. For a Symfony bundle, this is a transparency gap, although it does not by itself indicate unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.17 | — | — |
symfony/ux-autocomplete Version ^2.14 | — | — |
doctrine/doctrine-bundle Version ^2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.