Usable with caveats: this is a mature, tested PHP library with clear licensing and organization backing, but maintenance appears dormant. There have been no releases for about two years and no commits in the last three months, so verify that it still supports your PHP and Symfony versions.
58%
Total Score
67
100
88
67
The project has 60 releases over more than 13 years, but it has had no release in about two years. That long pause materially raises maintenance and compatibility risk despite the historically regular cadence.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is the strongest evidence that ongoing maintenance may have stalled.
There were no new or closed issues or pull requests in the last month, and no work is currently open. This is consistent with a quiet project but provides little evidence of active support.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence that the package is unsafe.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. This lowers transparency somewhat but is not by itself a reason to reject an otherwise established library.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 2.0.* | — | — |
symfony/cache Version 5.4.* || ^6.0 | — | — |
doctrine/cache Version ^2.1 | — | — |
symfony/validator Version 5.4.* | — | — |
doctrine/annotations Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.