Risky to adopt: the package has seen no repository activity for about 11 months after a tightly clustered launch. The linked repository does not identify or mention this package, and it has no tests, security policy, or meaningful adoption signals.
43%
Total Score
50
78
75
The repository is owned by an individual account rather than an organization, so there is no provided evidence of institutional backing to compensate for the thin activity record.
The package is about 11 months old but has only three releases, all concentrated within roughly two days in October 2025. This provides little evidence of sustained maintenance after launch.
There were no commits and no active maintainers in the last three months, following a last push about 11 months ago. This is the strongest evidence of stalled maintenance and abandonment risk.
The repository name does not match the package name, and its README does not mention the package. That mismatch raises a concrete concern that the linked source may not clearly belong to this release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external sign of adoption or community visibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 || ^7.0 | — | — |
symfony/config Version ^6.0 || ^7.0 | — | — |
symfony/http-client Version ^6.4 || ^7.0 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 | — | — |
symfony/dependency-injection Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.