Tests, a usable README, and release notes improve transparency. The single maintainer and absent security tooling leave little resilience for a package with limited ongoing project activity.
35%
Total Score
33
79
75
The package has had only two releases, both in December 2017, and none in the past 12 months. This strongly raises abandonment risk for a dependency released over eight years ago.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
Only one registry publishing maintainer is listed, leaving little visible capacity or redundancy if that maintainer becomes unavailable.
There is one open issue and no issue or pull-request activity in the last month. This is a modest warning when combined with the absent recent commits, though it is not severe by itself.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, partially offset by the package's small, straightforward file tree.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.3|^4.0 | — | — |
symfony/framework-bundle Version ^3.3|^4.0 | — | — |
qandidate/stack-request-id Version ^1.0 | — | — |
symfony/expression-language Version ^3.3|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.