The package is small and clearly licensed, with no install-time scripts or registry deprecation. Its documentation is minimal, and the source project shows no recent maintenance or security tooling.
43%
Total Score
25
100
57
75
The package has 12 releases since June 2013, but none in nearly 7 years; this strongly increases abandonment risk despite its earlier release cadence.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and indicating inactive maintenance.
A README is present, but it explicitly says documentation is not yet available. The absence of tests and a changelog is normal for a published package artifact and is not counted against it.
The repository is owned by an individual rather than an organization, so there is no provided evidence of broader project backing to offset the inactive maintenance record.
The repository name does not match the package name and its README does not mention the package, so the package-to-repository relationship is less transparent than expected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ruflin/elastica Version ^6 | — | — |
symfony/symfony Version >=3.4 | — | — |
friendsofsymfony/elastica-bundle Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.