Unfit to use for a new dependency: the package is deprecated and its source repository is archived, with no release in nearly four years. Licensing, release notes, and clear repository ownership provide transparency, but they do not offset the strong abandonment risk.
18%
Total Score
100
50
100
The registry marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk because future maintenance and compatibility should not be expected.
The package has a substantial history of 130 releases, but it has had no releases in the last 12 months and the latest release was nearly four years ago. The earlier cadence does not compensate for the prolonged inactivity.
The linked source repository is archived and was last pushed nearly four years ago. This indicates the project is no longer actively maintained, despite the repository matching the package and organization.
The assessed version is a beta release, while the registry reports a stable latest version profile. Using a beta further increases compatibility risk for a package that is already deprecated and archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^4.3 | — | — |
symfony/yaml Version ^4.3 | — | — |
symfony/config Version ^4.3 | — | — |
symfony/routing Version ^4.3 | — | — |
symfony/validator Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.