It has a clear MIT license, a substantial source tree, tests, and a security policy. Install scripts are absent, but all three workflow actions are unpinned.
42%
Total Score
50
63
83
The package has had no release in about six years and none in the last 12 months, despite 18 total releases. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release and indicating no observed maintenance capacity.
There were no new or merged pull requests and no issue activity in the last month. The unknown open-issue count limits the conclusion but does not provide evidence of ongoing work.
The repository has zero stars, forks, and watchers, so there is no visible community signal to compensate for the lack of recent maintenance. Popularity is supporting evidence rather than decisive on its own.
Composer is used for builds, but no security-scanning tool was detected. That is a modest transparency and maintenance gap for a dependency with a large runtime dependency set.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.3 | — | — |
axy/sourcemap Version ^0.1.4 | — | — |
doctrine/dbal Version ^2.7 | — | — |
illuminate/bus Version 5.7.* | — | — |
symfony/config Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.