Tests, a clear MIT license, and no install-time scripts improve transparency. Most workflow actions are unpinned and the repository has no security policy, limiting maintenance hygiene.
56%
Total Score
50
83
67
The latest release was over four years ago, with no releases in the preceding 12 months; this is a substantial sign of slowing maintenance, though the package has a stable release history rather than repeated failed releases.
There were no commits and no active maintainers in the last three months, reinforcing the concern that development has effectively stopped.
The repository has one star and one fork, indicating limited external adoption or review; this is supporting caution rather than a verdict by itself.
The project uses Make and Composer, but no security scanning tools were detected, leaving a modest source-maintenance gap.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^4.0 || ^5.1.5 | — | — |
symfony/http-kernel Version ^4.0 || ^5.1.5 | — | — |
symfony/dependency-injection Version ^4.1.12 || ^5.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.