The package has clear documentation, a changelog, an MIT declaration, and organization backing. Its dependency set is substantial, but the project shows no recent issue or security-policy activity, so future maintenance is uncertain.
42%
Total Score
50
75
75
The package has 23 releases over about 12 years, but none in the last 12 months and the latest release was nearly seven years ago. This strongly raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the broader evidence of prolonged inactivity.
There were no new or closed issues or pull requests in the last month, with 10 issues still open and one pull request open. This provides no evidence of current issue handling.
The repository has no security policy. That is a transparency and response-process gap, particularly for a package with no recent maintenance activity.
The assessed version is v3.0.0-alpha2 while the latest stable version is v2.1.7, so this release is a prerelease rather than an established stable line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0 | — | — |
symfony/form Version ^3.4 || ^4.0 | — | — |
symfony/config Version ^3.4 || ^4.0 | — | — |
fzaninotto/faker Version ^1.6 | — | — |
symfony/validator Version ^3.4 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.