Risky to adopt: Packagist marks this package abandoned and points users to a replacement. The linked organization repository is active and tested, but the deprecated registry package and repository/package naming mismatch make the replacement the safer dependency.
35%
Total Score
83
75
75
Packagist marks the entire package abandoned and identifies a replacement repository, which is a serious adoption risk even though the linked source remains active.
The package is young at 70 days, with five releases and a recent release 14 days after the previous median interval; this shows active iteration but limited maturity.
Two contributors are active, but one accounts for 80% of recent commits, leaving some continuity risk; organization backing provides partial compensation.
The repository name does not match the package name and its README does not mention the package, creating uncertainty that this source repository directly backs the published package.
No repository security policy is present, leaving vulnerability-reporting guidance unspecified; this is a transparency gap, though not decisive against the actively maintained source.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
symfony/config Version ^8.0 | — | — |
symfony/console Version ^8.0 | — | — |
articulate-orm/core Version ^2.0.0 | — | — |
symfony/http-kernel Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.