The package is clearly packaged, tested, licensed, and connected to a matching organization-owned repository. Maintenance has effectively stopped, leaving future compatibility and bug-fix support uncertain.
45%
Total Score
75
72
83
The latest release was in June 2015, with no releases in the last 12 months despite the package being about 11 years old. This is strong evidence of abandonment risk, although the release history was initially active.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long release gap. The repository was pushed in August 2022, so it is not completely untouched but is not actively maintained now.
The repository has only 3 stars and no forks, indicating limited adoption and community support. Popularity is supporting evidence, so this modestly increases maintenance uncertainty rather than determining the verdict.
The project uses Make and Composer, but no security scanning tools were detected. This is a hygiene gap, not a standalone reason to reject an otherwise maintained package.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This matters more because current maintenance activity is already weak.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.5 | — | — |
symfony/config Version ~2.5 | — | — |
symfony/finder Version ~2.5 | — | — |
symfony/console Version ~2.5 | — | — |
symfony/dependency-injection Version ~2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.