The MIT license, README, and small source tree make the package straightforward to inspect and integrate. Maintenance has effectively stopped, with no commits or issue activity for about six years, so compatibility fixes may not arrive.
45%
Total Score
50
75
88
The latest release was about six years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with a project that has stopped receiving maintenance.
There were no new or closed issues or pull requests in the last month, leaving little evidence of current support or upkeep.
The repository uses Make and Composer, but reports no security scanning tooling; this is a modest transparency and hygiene gap rather than a severe risk.
No security policy is present, reducing clarity about vulnerability reporting for a package with no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4|^5.0 | — | — |
symfony/http-kernel Version ^4.3|^5.0 | — | — |
phpmetrics/phpmetrics Version ^2.5 | — | — |
symfony/dependency-injection Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.