Documentation and packaging are clear, and the organization-backed repository matches the package. Its small audience and absent security policy add little reassurance for a release that should not be selected for new work.
15%
Total Score
50
50
67
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The latest release was published in March 2016, and there have been no releases in the last 12 months. This indicates prolonged abandonment rather than a merely slow release cycle.
The repository recorded zero commits and zero active maintainers during the last 3 months. This confirms that current maintenance is absent.
The repository is not formally archived, but it was last pushed in March 2016. The non-archived status does not compensate for more than 10 years without repository activity.
Post-install and post-update Composer scripts are part of the documented configuration workflow for generating app_loader.ini. They add operational complexity but are expected for this package's stated purpose.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^2.3|^3.0 | — | — |
sensio/distribution-bundle Version ^4.0|^5.0 | — | — |
wemakecustom/composer-script-utils Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.