The package has an MIT license, matches its source repository, and the repository includes tests. Its install-time scripts and missing security scanning add smaller maintenance concerns; pin this version only when continued support is not required.
38%
Total Score
50
71
50
Only four releases exist, with none in the last 12 months; the latest release was in November 2021, nearly five years ago. This strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release.
The package runs post-install and post-update Composer scripts, increasing installation complexity and the amount of package code executed during dependency changes.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a minor transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/routing Version ^5.3 | — | — |
symfony/http-kernel Version ^5.3 | — | — |
symfony/event-dispatcher Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.