The package has a clear README, MIT licensing, and a focused dependency set. Those positives do not offset the lack of ongoing project support.
15%
Total Score
0
50
100
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
The package has had four releases since October 2021, but none in the last four years. That long release gap reinforces the abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived state and lack of current maintenance.
The linked repository is archived and was last pushed more than four years ago, so upstream maintenance and issue response should not be expected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.4 || ^5.0 || ^6.0 | — | — |
jomweb/billplz Version ^4.1 | — | — |
symfony/config Version ^4.4 || ^5.0 || ^6.0 | — | — |
symfony/http-client Version ^4.4 || ^5.0 || ^6.0 | — | — |
symfony/http-kernel Version ^4.4 || ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.