The stable release, MIT licensing, tests, and release notes offer useful transparency. It is not a sound dependency choice while the package is deprecated, archived, and inactive.
12%
Total Score
50
64
50
Packagist marks the entire package as abandoned, with no replacement named; this is a direct warning against taking a new dependency on it.
The linked repository is archived, and its last push was about 2 years and 4 months ago, indicating the project is no longer maintained.
The package has a substantial history of 90 releases since 2015, but it has had 0 releases in the last 12 months; its earlier cadence does not compensate for the current halt.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the abandonment signal rather than showing ongoing maintenance.
No security policy was found in the linked repository, leaving the process for reporting and handling vulnerabilities unclear; the archived state makes this gap more consequential.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.10|^3.0 | — | — |
doctrine/orm Version ^2.8 | — | — |
symfony/lock Version ^6.4 | — | — |
symfony/yaml Version ^6.4 | — | — |
symfony/cache Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.