The codebase is small and clearly tied to the package, but its single publisher and lack of security policy leave little visible support. Four runtime dependencies are ordinary; maintenance appears to have stopped.
38%
Total Score
25
60
75
The latest release was published in December 2021, and there have been no releases in nearly five years. The 92 releases were concentrated at the project's start, so they do not offset the long current gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being nearly five years ago. No provided activity signal shows current maintenance.
The package declares no license, contains no license file, and the linked repository also has no license file. This leaves reuse and redistribution terms unclear for consumers.
Only one registry account can publish the package. The linked repository is user-owned rather than organization-owned, so there is little visible publishing redundancy, although this does not by itself prove abandonment.
The repository uses Composer but has no detected security-scanning tooling. This is a hygiene gap that adds some uncertainty, while the package's ordinary four-runtime-dependency profile provides limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 | — | — |
symfony/cache Version ^6.0 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
symfony/validator Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.