Risky to adopt without strong justification: the package has had no release or repository activity for about three years and nine months, with no tests or README to support maintenance or use. It is not deprecated or archived and has a license file, but the long-standing inactivity makes it a maintenance liability.
42%
Total Score
50
100
75
83
The package has published no releases in the last three years and nine months, despite seven releases overall. This long gap is strong evidence of stalled maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the prolonged release gap and indicating no recent maintenance capacity.
The package has no README, tests, or changelog, and the repository also reports no tests or changelog. Missing tests and project documentation reduce transparency and confidence for a Symfony library.
Composer is used for the project, which is appropriate, but no security scanning tooling is reported. The lack of scanning is a modest hygiene gap in an otherwise minimal project.
No security policy is present, leaving no documented process for reporting or handling vulnerabilities. This is a maintenance and transparency gap, though it is less severe than the inactivity signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/translation Version ^4.2||^5.0||^5.4 | — | — |
hello-jonzz/symfony-storage Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.