The project has a clear MIT license, a matching repository, repository tests, and Dependabot scanning. Its security policy is absent, and workflow references are not pinned, including one archived action.
68%
Total Score
50
100
93
75
The repository is owned by an individual rather than an organization, so there is no demonstrated organizational maintenance capacity to offset the thin recent contributor base.
The package has 34 releases over nearly 11 years, but none in the last 12 months; the latest release was about one year ago. This suggests slowed maintenance, although the long release history shows established use.
All one recent commit came from a single contributor, leaving maintenance dependent on one active person. The repository is individually owned, so there is no organization backing shown to compensate for this concentration.
Only one commit was recorded in the last three months, indicating very light recent development. The recent push provides some evidence of activity but does not offset the slow release cadence fully.
No security policy was found in the repository. For a parser library, this is a transparency gap, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/console Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.