The package is clearly identified, MIT-licensed, and has a small dependency footprint. Its README and GitHub release provide basic consumer guidance, but there is no security policy or scanning to support long-term maintenance.
38%
Total Score
0
100
81
50
This is the package's only release, published about 9 years and 6 months ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
The repository has had 0 commits and 0 active maintainers in the last 3 months, and its last push was about 9 years ago. The inactive source project provides little evidence of ongoing maintenance.
Composer is used as the build tool, which supports reproducible package structure, but no security scanning tools are configured. The missing scanning is a minor hygiene concern rather than evidence of unsafe behavior.
The repository has no security policy. This is a transparency and maintenance gap, although the package is small and no security issue is indicated by this signal alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.