The README and release notes make setup clear, and no install-time scripts reduce adoption friction. A single maintainer, no tests, no license, and no security policy leave limited evidence for long-term support.
38%
Total Score
33
50
72
83
This is the only release, published nearly five years ago, with no releases in the last 12 months. That strongly suggests abandonment risk, though the repository is not archived.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Nine runtime dependencies, including Symfony, Doctrine, and Twig components, create meaningful compatibility and maintenance surface for a package with no recent releases.
Neither the package nor the linked repository provides a declared license or license file. This creates a material adoption and redistribution concern.
Only one registry account has publishing access. The linked project is user-owned rather than organization-backed, so there is little visible publishing redundancy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
doctrine/orm Version ^2.9 | — | — |
symfony/form Version ^5.0 | — | — |
symfony/config Version ^5.0 | — | — |
symfony/routing Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.