Its MIT declaration, complete README, and repository tests support transparency. The project has no security policy or scanning, and its 11 runtime dependencies add maintenance surface. The archived, abandoned project should not be adopted for new dependencies.
8%
Total Score
0
42
50
Packagist marks the entire package as abandoned, with no replacement identified. This is a direct warning against taking a dependency on this release.
The latest release was published about 4 years and 9 months ago, and there were no releases in the last 12 months. This strongly indicates abandonment rather than a merely slow release cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its archived state and the package's abandonment warning.
The linked repository is archived and was last pushed about 4 years and 5 months ago, indicating the source is no longer actively maintained.
Composer build tooling is present, but no security-scanning tools were detected. That leaves a modest supply-chain hygiene gap in an otherwise inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4 | — | — |
symfony/string Version ^5.4 | — | — |
symfony/contracts Version ^2.3 | — | — |
symfony/validator Version ^5.4 | — | — |
zikula/core-bundle Version 3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.