Usable with caveats: it has clear licensing, documentation, repository tests, and no deprecation, but the only release was in 2017 and the repository has had no recent commits. Depend on it only if its old Symfony and PHP integration remains compatible with your project.
58%
Total Score
50
100
72
83
The package has had only one release, published about 9 years ago, with no releases in the last 12 months. This is strong evidence of a stagnant release process and raises compatibility and abandonment concerns.
There were no commits and no active maintainers in the measured last 3 months. Combined with the single old release, this indicates a project with little or no current maintenance capacity.
There are two open issues and no new or closed issues or pull requests in the last month. The small issue volume is not severe, but the lack of recent activity is consistent with an inactive project.
The repository has only 6 stars, 8 forks, and 1 watcher. This is limited supporting evidence and does not independently make the package unsafe, but it offers little community backup for an aging dependency.
The repository uses Composer for builds, but no security-scanning tools were detected. For an old package this reduces ongoing transparency around dependency and code risks, though it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^3.1 | — | — |
egeloen/serializer Version ^1.0 | — | — |
symfony/framework-bundle Version ^2.7|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.