It is MIT-licensed, has repository tests and a changelog, and uses no install-time scripts. The source remains identifiable and the package is not deprecated, but maintenance evidence is too weak for a new dependency.
38%
Total Score
0
50
75
75
The package has had no release in the last 12 months, and its latest release was published on June 25, 2018, more than eight years ago. This strongly indicates stalled maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and providing no evidence of current maintenance.
The package declares 14 runtime dependencies, including several framework components. This is a substantial dependency surface for a legacy compatibility bundle, though the signal alone does not show that the dependencies are unsafe.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a minor transparency and maintenance concern, especially for a package with no recent activity.
The linked repository is not archived, which is a modest positive, but its last push was on June 25, 2018 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^2.8 || ^3.2 || ^4.0 | — | — |
symfony/console Version ^2.8 || ^3.2 || ^4.0 | — | — |
symfony/translation Version ^2.8 || ^3.2 || ^4.0 | — | — |
symfony/security-acl Version ^2.8 || ^3.0 | — | — |
symfony/security-core Version ^2.8 || ^3.2 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.