The dependency set is small and the MIT declaration is clear. The package has not changed since April 2022, with no README in the published library and no security scanning, so long-term maintenance is a liability.
43%
Total Score
50
100
58
50
The latest release was about 4 years and 5 months ago, with no releases in the last 12 months. Its earlier release cadence was active, but the prolonged halt is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the registry's long release gap. This leaves little evidence of ongoing maintenance.
The package has no README, which makes a library harder to integrate and understand. Missing tests and a changelog are normal for published artifacts and are not concerns here.
The repository name does not match the package name, and no README package reference was available. Although a name mismatch can be normal for a sub-package, the missing corroborating mention creates some ownership uncertainty.
Composer is used for builds, but no security-scanning tool is configured. That weakens maintenance and vulnerability-detection transparency, although it does not by itself indicate an unsafe package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/routing Version 4.2.*||5.* | — | — |
symfony/translation Version 4.2.*||5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.