38%
Total Score
unhealthy
No releases since 2014, no recent commits, and the latest version remains a prerelease.
The latest of five releases was published in September 2014, with no releases in the last 12 months. This long release gap is strong evidence of abandonment risk despite the earlier regular cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the old registry history, this points to sustained inactivity rather than a short pause.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools were detected, leaving a modest transparency gap, but this is less significant than the maintenance evidence.
The repository has no security policy. This reduces reporting transparency, though it is a secondary concern for this small package compared with its prolonged inactivity.
Version 1.1.0-rc.2 is still a prerelease, and all recent releases are prereleases. That indicates the package never reached a stable release line.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.2 | — | — |
appsco/component-jwe Version ~1.0 | — | — |
symfony/http-foundation Version ~2.2 | — | — |
appsco/appsco-php-client Version * | — | — |
symfony/dependency-injection Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.