Unfit to use: the package is deprecated and its source repository is archived. Its long release history, tests, documentation, and stable version do not offset the lack of current maintenance.
18%
Total Score
0
63
67
Packagist marks the entire package as abandoned, with no replacement identified. A package-level deprecation is a severe adoption risk because future fixes and support are uncertain.
There were no commits and no active maintainers in the last 3 months. Combined with the archived repository, this confirms that current development activity is absent.
The linked repository is archived, which strongly indicates that active maintenance has ended even though it was pushed recently. This is a severe abandonment risk for a dependency.
The package has a substantial history of 57 releases since September 2013, but it has had no releases in the last 12 months and its latest release was in February 2025. The established history is positive, while the current gap is a serious maintenance concern.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a hygiene gap, though it is secondary to the package's explicit abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.40 || ^2.9 || ^3.0 | — | — |
symfony/form Version ^2.8 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
symfony/yaml Version ^2.8 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
google/recaptcha Version ^1.1 | — | — |
symfony/validator Version ^2.8 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.