Seven runtime dependencies increase upgrade exposure, and the 0.2 line offers little maturity signal. The source repository could not be found, so maintenance and provenance cannot be checked.
35%
Total Score
50
50
The latest release was about 13 years ago, with only two releases and none in the last 12 months. This is strong evidence of abandonment risk despite the package not being deprecated.
The package declares seven runtime dependencies and no development dependencies, creating a meaningful upgrade surface. The profile is not inherently unsafe, but it adds maintenance exposure for an old release.
The latest version is v0.2.0, which remains below a stable major release. That reinforces the package's limited maturity, although it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/react Version 0.3.* | — | — |
symfony/yaml Version 2.3.* | — | — |
erpk/harvester Version dev-master | — | — |
symfony/config Version 2.3.* | — | — |
symfony/console Version 2.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.