The stable major release, MIT license, tests, and direct package mention make the artifact relatively clear to integrate. The repository has no recent work or security policy, so long-term support is unlikely.
20%
Total Score
50
100
69
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption concern rather than a warning limited to version 2.0.5.
The package has 9 releases, but its latest release was in April 2017 and it had no releases in the last 12 months. That nearly nine-year release gap indicates abandonment risk.
The linked repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and offering no evidence of ongoing maintenance.
The project uses Composer, but no security-scanning tooling was detected. This is a modest hygiene gap and does not offset the package's inactive status.
The repository has no security policy. This is a transparency and response-process gap, although it is secondary to the package's abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
victoire/victoire Version >=2.0.0|~3.0 | — | — |
symfony/framework-bundle Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.