The package includes tests, a substantial README, and a matching source repository. Its install scripts add some maintenance exposure, while the project has no recent development activity or security policy.
10%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption warning and outweighs the otherwise useful package metadata.
The latest release was in March 2013, with no releases during the last 12 months and only six releases overall. The long period without releases strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms that there is no current maintenance capacity.
The linked repository is archived and was last pushed in June 2015, indicating the project is no longer maintained. This independently makes relying on the release risky.
The package defines post-install and post-update scripts. These increase installation complexity and maintenance exposure, though this is secondary to the package's abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.* | — | — |
symfony/console Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.