Documentation and packaging are solid, and the project has clear organization ownership. The absence of security scanning adds a smaller concern, while the lack of releases and commits for years makes this a poor long-term dependency.
34%
Total Score
67
100
78
88
The package has had no release in about 9 years and 8 months: all 23 releases are from January 2017, with none in the last 12 months. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive since July 2017.
The repository has zero stars and forks and only four watchers, providing little supporting evidence of active community use. Popularity is secondary, but this reinforces the maintenance concern.
Composer is used for builds, but no security-scanning tools are present. The missing scanning is a modest transparency and maintenance gap, not proof of unsafe code.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance response. This is secondary to the much stronger inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 | — | — |
doctrine/inflector Version ^1.0 | — | — |
symfony/serializer Version ^3.1 | — | — |
symfony/http-kernel Version ^2.7 || ^3.0 | — | — |
symfony/property-info Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.