The MIT declaration conflicts with the GPL-2.0 license file, and the repository does not clearly identify this package. Tests, release notes, and a complete source tree help explain the release, but they do not offset its abandonment.
12%
Total Score
0
33
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe warning against taking a new dependency on the release.
Only two releases exist, with no release in more than six years and no releases in the last 12 months. This strongly indicates abandonment rather than an actively maintained stable package.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the archived state, this shows no current maintenance capacity.
The source repository is archived and was last pushed more than six years ago, indicating the project is no longer maintained.
The package declares MIT, but its included license file is recognized as GPL-2.0. The release is licensed, but the mismatch creates an important compliance ambiguity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
twig/twig Version ^1.42 | — | — |
doctrine/orm Version ^2.5 | — | — |
symfony/config Version ^3.4 | — | — |
doctrine/common Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.