The package is documented, tested, licensed, and has a clear matching repository. Its small user base and lack of security tooling leave less independent assurance if maintenance does not resume.
60%
Total Score
50
83
50
The package has 35 releases and a rapid historical median interval of about 6 days, but it has had no release in the last two years. That recent halt is a meaningful maintenance concern despite the strong earlier cadence.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the extended release pause. This raises abandonment risk.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of a broad external user or contributor base. Low popularity is supporting caution rather than a verdict on its own.
Composer is used as the build tool, but no security scanning tools are present. The missing automated security checks reduce assurance for a package with many runtime dependencies.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities. This is a transparency gap, though it does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.4 || ^5.4 | — | — |
symfony/config Version ^4.4 || ^5.4 | — | — |
symfony/console Version ^4.4 || ^5.4 | — | — |
symfony/messenger Version ^4.4 || ^5.4 | — | — |
symfony/serializer Version ^4.4 || ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.