Unfit to use for a new dependency: the source repository is archived and has had no commits or active maintainers in the last three months. The release history also shows no release in over three years, despite the package having tests, licensing, and a clear source tree.
20%
Total Score
50
64
67
There have been 0 releases in the last 12 months, and the latest release was on May 31, 2023. The long release gap is consistent with the repository being abandoned.
The repository recorded 0 commits and 0 active maintainers in the last three months, reinforcing that maintenance has stopped rather than merely slowed.
The linked repository is archived, with its last push on May 31, 2023. An archived project is a severe abandonment risk for a package intended to support application development.
Two of six workflows use pull_request_target, which can require careful privilege handling. No untrusted checkout or script injection was detected, so this is a limited workflow concern rather than the reason for the low score.
The repository uses Composer, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is secondary to the repository's archived status.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 | — | — |
doctrine/dbal Version ^2.10 | — | — |
symfony/config Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/dependency-injection Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.