The package has a README, extensive tests, a stable version, and a matching source repository. Its dependency surface is broad and the project lacks security scanning, which adds maintenance and transparency concerns.
35%
Total Score
0
50
81
100
The latest release was nearly 12 years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a library with many runtime dependencies.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap. The available activity does not show ongoing maintenance.
The package declares 14 runtime dependencies, including framework, ORM, serializer, and tooling components. This broad dependency surface increases the cost and risk of relying on an unmaintained package.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, although it is less serious than the absence of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silex/silex Version ~1.2 | — | — |
doctrine/orm Version ~2.3 | — | — |
jms/serializer Version 0.16.0 | — | — |
symfony/finder Version ~2.3 | — | — |
symfony/process Version ~2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.