The repository has had no commits or releases for about four years, and its sole publisher account offers little maintenance depth. The proprietary license, absent security policy, package-name mismatch, and unpinned workflow actions add transparency and supply-chain concerns.
42%
Total Score
63
100
69
67
The package has made no releases in the last 12 months, and its latest release was about four years ago. This is strong evidence of abandonment risk for a dependency released as recently as v2.0.0.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push and release history, this materially raises abandonment risk.
The manifest declares a proprietary license, but no license file was detected in the package or repository. That limits clarity for developers evaluating redistribution and long-term use.
There are no open issues or pull requests, and no recent issue or pull request activity. This is neutral for a small stable project but provides no evidence of active maintenance.
The repository name does not match the package name and its README does not mention the package. Although name differences can occur in subpackages, this combination leaves uncertainty about whether the linked repository actually corresponds to the published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
symfony/cache Version ^5.4 || ^6.0 | — | — |
symfony/config Version ^5.4 || ^6.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.