It has a small but real test suite, a matching repository, and an MIT license. The README says it is not ready for use, while the project shows no security policy or scanning.
38%
Total Score
0
61
83
This package has only one release, published more than 12 years ago, with no releases in the last 12 months. That is strong evidence of abandonment rather than an established release practice.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this indicates that maintenance has effectively stopped.
The artifact includes a README and tests, which provide useful consumer and maintenance evidence. However, the README explicitly says the project is “Not ready for use,” and there is no changelog or release note for this version.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these counts provide no external maintenance or adoption signal to offset the age and inactivity.
The project uses Composer build tooling, but no security-scanning tools were detected. For an old library this leaves a meaningful transparency and maintenance gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version 2.4.*@dev | — | — |
symfony/config Version 2.4.*@dev | — | — |
symfony/finder Version 2.4.*@dev | — | — |
symfony/filesystem Version 2.4.*@dev | — | — |
symfony/event-dispatcher Version 2.4.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.