The repository has no recent commits, tests, or security policy, leaving little evidence of ongoing care. A license file and matching repository make the package transparent, but the maintenance gap is substantial.
40%
Total Score
0
71
50
The latest release was in October 2022, and there have been no releases in nearly four years despite nine total releases. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
The package includes a very short 32-character README and no tests or changelog. Missing tests and changelog are normal in published artifacts, but the minimal consumer documentation leaves a real transparency gap.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap that reinforces the limited evidence of ongoing care.
No security policy was found, so users have no documented process for reporting vulnerabilities. This adds a maintenance and transparency concern, though it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imper86/ddd Version ^2.0 | — | — |
symfony/config Version ^6.0 | — | — |
symfony/messenger Version ^6.0 | — | — |
symfony/http-kernel Version ^6.0 | — | — |
symfony/framework-bundle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.