The release includes a clear README, tests, changelog, and MIT licensing. Its small audience, absent security policy, and loosely pinned workflow actions reduce confidence in long-term support.
38%
Total Score
50
50
61
50
Packagist marks the entire package as abandoned, even though the listed replacement has the same name; that directly lowers confidence in taking a dependency on this package.
The latest registry release was in April 2020, with no releases in the last 12 months; this is a substantial maintenance and abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history concern despite a later push timestamp elsewhere in the metadata.
The package has 11 runtime dependencies, including several Symfony components and third-party bundles, creating meaningful ongoing compatibility and maintenance exposure.
Post-install and post-update scripts add execution during dependency operations, increasing review and maintenance burden compared with a package without install-time behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^4.2.12 || ^5.0 | — | — |
symfony/validator Version ^4.2.12 || ^5.0 | — | — |
symfony/translation Version ^4.2.12 || ^5.0 | — | — |
symfony/http-foundation Version ^4.2.12 || ^5.0 | — | — |
symfony/property-access Version ^4.2.12 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.