The linked repository has also seen no recent commits, and it does not identify this package in its name or README. Licensing, documentation, tests, and organization backing are present, but they do not offset the age and identity concerns.
42%
Total Score
63
100
75
83
The package has had no release in over five years, despite 76 releases overall. That long gap is strong evidence of abandonment risk for a maintained dependency.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this materially raises abandonment risk.
There was no issue or pull-request activity in the last month, which is consistent with the broader signs of a dormant project.
The repository name does not match the package name and its README does not mention the package. That raises concern that the linked repository may not actually be the source for this release.
Composer build tooling is present, but no security-scanning tooling was detected. This is a transparency and maintenance gap rather than a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.40|^2.9|^3.0 | — | — |
symfony/mime Version ^4.3|^5.0 | — | — |
symfony/finder Version ^3.4|^4.3|^5.0 | — | — |
imagine/imagine Version ^0.7.1|^1.1 | — | — |
symfony/process Version ^3.4|^4.3|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.