Unfit to use for a new dependency: the package is deprecated and its repository is archived, with no commits or releases in roughly two years. It has clear ownership, tests, documentation, and licensing, but those positives do not offset the lack of ongoing maintenance.
18%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because future fixes and compatibility work are not indicated.
The package has a substantial history of 145 releases, but it had no releases in the last 12 months and its latest release was in July 2024. Historical maturity does not compensate for the current release gap.
The repository recorded zero commits and zero active maintainers in the last three months. This directly supports the conclusion that maintenance has stopped.
The linked source repository is archived, confirming that it is no longer intended for active development. Its last push was in July 2024, so the release has no ongoing upstream maintenance.
One of six workflows uses pull_request_target, which warrants review because it can run with elevated repository context. No untrusted checkout or script-injection patterns were detected, limiting the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.0 | — | — |
symfony/console Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
netgen/query-translator Version ^1.0.2 | — | — |
symfony/framework-bundle Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.