The project is tiny, with one star and no repository tests or security policy. It is MIT-licensed, not deprecated or archived, and has a clear package tree and README.
43%
Total Score
72
50
This package has only one release, published about 5 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The published artifact includes a README and the exact version has a GitHub release; the absence of tests and a changelog in the artifact is normal packaging practice. The repository also reports no tests, which limits confidence in ongoing maintenance.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these very low numbers provide little evidence of community review or project resilience.
Composer is used as a build tool, but no security scanning tools are present. This is a modest transparency and maintenance gap for a package with no recent release activity.
The repository has no security policy. That reduces transparency for reporting and handling issues, especially alongside the absence of recent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^3.4.30|^4.3|^5.0 | — | — |
symfony/config Version ^3.4.30|^4.3|^5.0 | — | — |
symfony/http-kernel Version ^3.4.30|^4.3|^5.0 | — | — |
symfony/http-foundation Version ^3.4.30|^4.3|^5.0 | — | — |
symfony/event-dispatcher Version ^3.4.30|^4.3|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.