The artifact contains substantial PHP source and no install-time scripts, but its license signals conflict and consumer documentation is absent. The repository could not be found, so maintenance and provenance cannot be verified.
38%
Total Score
60
100
The package has had no release in nearly six years; its latest release was November 2020, which is strong evidence of abandonment risk despite seven total releases.
The manifest declares a proprietary license, while the included LICENSE file is detected as GPL-3.0. This unresolved mismatch creates genuine legal and adoption uncertainty.
The package has no README, which makes a library harder to integrate. The absence of tests and a changelog is normal for a published artifact and is not treated as a gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/cache Version 5.0.* | — | — |
symfony/config Version 5.0.* | — | — |
symfony/messenger Version 5.0.* | — | — |
symfony/http-kernel Version 5.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.