The source project remains maintained enough to provide tests, documentation, and a matching organization-owned repository. Its MIT licensing and lack of install scripts reduce adoption friction, but the package should be replaced rather than newly adopted.
42%
Total Score
75
64
83
Packagist marks the entire package as abandoned and names araise/search-bundle as its replacement. This is a substantial adoption risk even though the release itself is not individually withdrawn.
The latest registry release was on August 19, 2022, with no releases in the last 12 months. That long release gap raises abandonment and compatibility risk.
The repository had no commits and no active maintainers in the last 3 months, which conflicts with the repository's recent push metadata and provides little evidence of ongoing development.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than a standalone adoption blocker.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations unclear. This is a transparency weakness, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version ~4.0|~5.0 | — | — |
whatwedo/core-bundle Version ^0.4 | — | — |
symfony/framework-bundle Version ~4.0|~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.