The MIT license, documented usage, and organization-backed repository improve transparency. However, the project shows no release or commit activity for about 12 years, and its repository does not identify or mention this package; its lack of a security policy adds further maintenance uncertainty.
38%
Total Score
67
100
72
75
The last release was published about 12 years ago, with no releases in the past year. This is strong evidence of abandonment for a dependency intended for ongoing use.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and indicating substantial abandonment risk.
There is no recent issue or pull-request activity. With no open backlog this is not itself severe, but it provides no evidence of ongoing project engagement.
The repository name does not match the package name and its README does not mention the package. That leaves uncertainty about whether the linked source repository actually corresponds to this release.
The repository has 1 star and no forks, offering little supporting evidence of a broad user or contributor community. Popularity is secondary, but there is no compensating activity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version >=2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.