The small codebase has no tests, changelog, or README, and its security policy and scanning setup are absent. It is licensed and not archived or deprecated, but the long maintenance gap makes new adoption a liability.
32%
Total Score
75
50
67
83
The latest release was 10 years ago, with no releases in the last 12 months; this strongly indicates abandonment risk despite six historical releases and a previously regular 18-day median interval.
The package has five runtime dependencies and no development dependencies. The dependency count is moderate, though the absence of development dependencies offers little evidence of a maintained test or development setup.
One registry maintainer is consistent with an individual-owned repository, so the count is not concerning by itself. However, it leaves little redundancy if that maintainer stops publishing.
The artifact and repository have no README, tests, or changelog. For a small command-line package, missing tests and changelog are not significant packaging gaps, but the missing consumer-facing README reduces transparency.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.6 | — | — |
symfony/config Version ^2.6 | — | — |
symfony/console Version ~2.6 | — | — |
guzzlehttp/guzzle Version ^5.2 | — | — |
symfony/dependency-injection Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.