The package includes tests, a README, Composer tooling, and Psalm scanning. Its workflow has no reported audit findings, but all 11 actions are unpinned, so adopting this old prerelease carries substantial maintenance risk.
40%
Total Score
0
78
67
The package has had no releases in the last 12 months, and its latest registry release was about 8 years ago. This is strong evidence of abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although it was pushed in 2023, current development activity is absent.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional confidence in project maturity or continuity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less serious than the clear maintenance concerns.
The assessed version is a prerelease alpha, and all recent releases are prereleases. That leaves API and support expectations less mature than a stable release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
symfony/yaml Version ~2.3||~3.0||~4.0 | — | — |
symfony/config Version ~2.3||~3.0||~4.0 | — | — |
symfony/finder Version ~2.3||~3.0||~4.0 | — | — |
symfony/console Version ~2.3||~3.0||~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.