The MIT license and complete source tree make inspection and redistribution straightforward. Organization ownership and a stable release do not offset the lack of active maintenance.
38%
Total Score
75
75
83
The package includes a readable README, but it explicitly says the package is read-only and that pull requests and support should go to the main project. The absence of published tests and a changelog is normal for an artifact and is not penalized.
The package has 59 historical releases, but none in the last 12 months; the latest release was nearly 10 years ago. This is strong evidence of abandonment despite its formerly regular release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that the project is no longer actively maintained.
The repository name does not exactly match the package name and its README does not contain the full package identifier. This is a mild ownership and packaging-transparency concern, though naming differences are common for project repositories.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This adds a maintenance and transparency gap for a package with no recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
elcodi/metric Version ^2.0 | — | — |
symfony/config Version ^2.7|^3.0 | — | — |
doctrine/common Version ^2.5 | — | — |
snc/redis-bundle Version ^1.1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.