Risky to adopt: the package has had no release since 2017 and remains an alpha version, with no repository commits in the last three months. It is licensed, documented, and tested, but the long-standing inactivity makes abandonment a serious concern.
32%
Total Score
25
58
100
The latest release was published in March 2017, and there have been no releases in the last 12 months despite the package being over 11 years old. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this points to a project that is no longer actively maintained.
There was no issue or pull-request activity in the last month, and one pull request remains open. This provides no evidence of current maintenance or responsiveness.
Composer build tooling is present, but no security scanning tools were detected. The tooling gap is a secondary transparency concern, while the more important maintenance risk comes from the inactive project.
The repository is not formally archived, which is a positive sign, but its last push was in April 2017 and does not offset the separate evidence of prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/xml Version ^1.5 | — | — |
symfony/yaml Version 2.* | — | — |
symfony/finder Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.