Healthy and suitable to depend on, with some maintenance caveats. It has a long release history, a current stable release, active organizational backing, tests, and a recent GitHub release; however, recent work is concentrated in one contributor and the repository lacks a security policy.
78%
Total Score
63
50
94
80
Six runtime dependencies are a moderate dependency surface for an archive-management library, including filesystem, process, and HTTP components; this is reasonable but adds maintenance exposure.
One contributor made all recent commits, creating a low short-term bus factor. Organizational ownership provides some handoff capacity, so this is a concern rather than a severe abandonment signal.
The repository recorded 11 commits in the last 3 months, showing recent work, but all activity came from one active maintainer.
There are 36 open issues and no issues or pull requests were closed or merged in the last month, indicating unresolved maintenance workload despite one open pull request.
Composer build tooling is present, but no security scanning tool was detected, leaving a gap in automated security maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.0 || ^7.0 | — | — |
symfony/filesystem Version ^6.0 || ^7.0 | — | — |
symfony/http-client Version ^6.0 || ^7.0 | — | — |
doctrine/collections Version ~1.0 | — | — |
symfony/polyfill-mbstring Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.