The package includes a usable README, tests, an MIT license, and a repository that clearly matches its name. Its old Symfony-era dependencies and missing security policy add concerns beyond the long-standing lack of maintenance.
28%
Total Score
25
70
50
The package has had no release in roughly 13 years: its latest release was in July 2013, with zero releases in the last 12 months. This is strong evidence of abandonment for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating no visible ongoing maintenance.
Only one registry publishing maintainer is listed, and the project is backed by a user-owned repository rather than an organization. That leaves limited visible maintenance capacity, especially alongside the inactive repository.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to offset the package's inactivity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less significant than the evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version >=2.2.3,<2.4-dev | — | — |
jms/serializer Version 0.13.*@dev | — | — |
symfony/symfony Version 2.3.* | — | — |
jms/di-extra-bundle Version ~1.4 | — | — |
jms/serializer-bundle Version 0.12.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.