Licensing is unresolved, and the consumer documentation is only an 18-character heading. The matching source tree and absence of install scripts help, but the package offers little evidence of ongoing project hygiene.
38%
Total Score
0
64
100
The last release was in March 2017, with zero releases in the past 12 months. Although the package is not deprecated, this long release gap is strong abandonment evidence.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history and indicating no current maintenance.
No declared license or license file was found in the package or repository, leaving the legal terms for dependency use unresolved.
The package includes a README, but it is only an 18-character heading and provides almost no consumer guidance. Missing published tests and changelog files are normal packaging practice and are not counted against it.
Composer is used for builds, which is appropriate, but no security scanning tooling was found. This is a modest transparency and maintenance gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
symfony/yaml Version ^3.1 | — | — |
jms/serializer Version ^1.1 | — | — |
monolog/monolog Version ^1.19 | — | — |
phpunit/phpunit Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.