The package is not deprecated and has only two runtime dependencies, which limits immediate complexity. A single listed maintainer and the repository could not be found, further reducing confidence in ownership and upkeep.
32%
Total Score
50
100
50
The latest release was about 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having four historical releases.
Only one registry account has publish access. This does not prove poor maintenance, but it provides limited visible continuity when combined with the long release gap.
Version 0.2.2 is not marked as a prerelease, which avoids one maturity concern, but the low major version and very old release date provide little evidence of ongoing stability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dependency-injection Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.