The package has little verification or security process. Its source and registry history show a project that has not been maintained since 2014 and is explicitly not production-ready.
18%
Total Score
0
25
50
The artifact includes a README, but it is only 51 characters and explicitly says the project is not ready for production. The GitHub release provides some release hygiene, but does not offset that warning.
The package has had only 3 releases, all around its first release in April 2014, with no release in over 12 years. This is strong evidence of abandonment rather than an actively maintained dependency.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository's last activity being in 2014. This indicates a severe abandonment risk.
The repository is not formally archived, but its last push was in May 2014. This partially confirms the release-history concern and indicates no meaningful maintenance despite the repository remaining available.
The repository name does not match the package name and its README does not mention the package. That makes the source relationship less transparent, although the repository URL otherwise follows the package's namespace.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ~2.3 | — | — |
symfony/config Version ~2.3 | — | — |
symfony/http-kernel Version ~2.3 | — | — |
symfony/dependency-injection Version ~2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.