A clear README, tests, and MIT licensing help consumers understand and use the package. Its small repository footprint and lack of security tooling add modest concern, but the long period without maintenance is the main problem.
40%
Total Score
0
67
50
This package has only one release, published about 11 years ago, with no releases in the last 12 months. The absence of newer releases is strong evidence that maintenance has stopped.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with its last push being about 11 years ago. No other activity signal compensates for this long maintenance gap.
The repository has only 3 stars and 1 fork, indicating limited adoption and external validation. Popularity is supporting evidence rather than decisive, but it provides little compensation for the inactivity.
Composer build tooling is present, but no security scanning tool is configured. That is a transparency and maintenance weakness, though it is secondary to the package's prolonged inactivity.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This matters more for a dependency that has also seen no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
symfony/config Version ~2.6 | — | — |
symfony/console Version ~2.6 | — | — |
symfony/process Version ~2.6 | — | — |
symfony/event-dispatcher Version ~2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.