Unfit to use: the source repository is archived and has had no commits or releases since March 2022. The assessed v3.3.0 also conflicts with the registry’s reported latest version v2.5.7, leaving serious maintenance and release-transparency concerns.
15%
Total Score
50
100
63
67
Although the package has 82 releases since 2016, its latest release was March 21, 2022, with no releases in the last 12 months; the long gap materially increases abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived state and indicating no active maintenance.
The linked repository is archived, with its last push on March 21, 2022; archived source is a severe abandonment risk for a dependency.
One of three workflows uses pull_request_target, which can carry elevated workflow risk even though no untrusted checkout or script injection was detected.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency gap, though it is secondary to the repository’s abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/event-dispatcher Version ^5.0 | — | — |
ezsystems/ezplatform-kernel Version ^1.3 | — | — |
symfony/dependency-injection Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.