The MIT license, matching repository, and clean package layout improve transparency. The dependency set is nontrivial and the repository lacks security scanning, so maintenance changes may be harder to assess.
42%
Total Score
50
50
69
83
This package has had only one release, published roughly eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive for roughly seven years.
Seven runtime dependencies, including Symfony components and a tracing client, create a meaningful compatibility surface for an old package.
The repository has zero stars, two forks, and one watcher. This offers little supporting evidence of community adoption, though popularity is not decisive.
Composer is used for builds, but no security scanning tools were detected. That leaves an avoidable transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~3.4|~4.0 | — | — |
symfony/console Version ~3.4|~4.0 | — | — |
symfony/http-kernel Version ~3.4|~4.1 | — | — |
symfony/serializer-pack Version ^1.0 | — | — |
symfony/dependency-injection Version ~3.4.6|~4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.