Clear packaging, licensing, tests, and release notes make the artifact understandable and reproducible. Maintenance has gone quiet, with no commits or issue movement recently, and the repository lacks a security policy.
58%
Total Score
33
50
81
75
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This is the strongest abandonment concern in the collected evidence.
The package declares 16 runtime dependencies, including several Symfony and data-processing components. This is a substantial dependency surface that increases upgrade and compatibility maintenance burden, without evidence here of a dependency failure.
The repository is owned by an individual user rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing for a project whose recent maintenance has stopped.
The package has six releases since April 2020, but it has had no release in the last 12 months; the latest release was December 22, 2024. This indicates a meaningful maintenance slowdown for a tool with ongoing dependencies.
There are 10 open issues, with no new or closed issues and no pull-request activity in the last month. This suggests limited current project attention, though the short observation window makes it a secondary concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/yaml Version ^7.0 | — | — |
flow/jsonpath Version ^0.5.0 | — | — |
symfony/dotenv Version ^7.2 | — | — |
symfony/finder Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.