Its MIT licensing, matching repository, and clear package structure support transparency. However, maintenance appears to have stopped over 10 years ago, and the package explicitly redirects issues and support to the main project.
40%
Total Score
50
100
70
83
The package has 88 releases, but its latest release was over 10 years ago and it had no releases in the last 12 months. This strongly indicates abandonment despite its historically active cadence.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the last push occurring in 2016. The organization backing does not compensate for the lack of observed maintenance.
The artifact includes a readable README, but it explicitly says the package is read-only and directs issues, questions, and pull requests to the main project. Missing tests and changelog files are normal packaging practice and are not concerns here.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is secondary to the long-standing inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elcodi/core Version ^2.0 | — | — |
doctrine/orm Version ^2.5 | — | — |
doctrine/common Version ^2.5 | — | — |
symfony/expression-language Version ^2.7|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.