The package is clearly documented and licensed, with a small focused dependency set. Its organization-backed repository remains unarchived, but there has been no commit or issue activity for more than 9 years and no security scanning or policy.
35%
Total Score
50
100
78
83
The last release was published more than 9 years ago, with no releases in the past 12 months. Although the package had eight releases and a stable history, this long silence is a substantial abandonment concern.
There were zero commits and zero active maintainers in the past 3 months, following a last repository push more than 9 years ago. This is strong evidence that maintenance has effectively stopped.
There were no new or closed issues or pull requests in the past month. Combined with the long release and commit silence, this provides no evidence of active support.
The repository has no stars or forks and one watcher. Popularity is only supporting evidence, but these very low engagement figures provide no additional confidence in continued maintenance.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning reduces transparency around ongoing dependency and build risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
symfony/yaml Version ^2.8 || ^3.0 | — | — |
bengor-user/user Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.