Its compact source tree includes a changelog and a matching organization-owned repository. The long period without releases or commits, plus absent tests and security scanning, makes future fixes and compatibility support uncertain.
43%
Total Score
50
50
72
88
The latest release was published in December 2020, with no releases in the following five years and nine months. This is strong evidence of abandonment risk, although the package is not marked deprecated or archived.
There were zero commits and zero active maintainers in the last three months, consistent with the release gap and materially increasing abandonment risk.
The package declares ten runtime dependencies, including framework and extension requirements, creating a relatively broad compatibility surface. The signal does not show these dependencies are unsafe or unmanaged, so this is only a modest concern.
One registry publishing account is listed, but this is administrative access information rather than evidence of active maintenance. The organization-owned project backing provides some context but does not compensate for the inactivity.
The package includes a changelog, and the absence of tests is normal for a published artifact. However, the missing README reduces consumer guidance for this PHP library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.7 | — | — |
nesbot/carbon Version ^2.27 | — | — |
beberlei/assert Version ^3.2 | — | — |
symfony/security-bundle Version ^5.1 | — | — |
symfony/serializer-pack Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.