The package has a clear license, usable documentation, and a small repository with no install-time scripts. Its stable release is also the latest, but maintenance stopped in October 2017 and Packagist marks the package abandoned with no replacement.
18%
Total Score
0
69
75
Packagist marks the entire package abandoned, with no replacement specified. This is a severe adoption risk despite the other healthy metadata.
The latest release was published in October 2017, and there have been no releases in the last 12 months. This strongly indicates abandonment for a Symfony integration package.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the package's long maintenance gap.
Composer is used for the build, which is appropriate for a Packagist package. No security scanning tools are present, a minor transparency gap, but it is outweighed by the abandonment evidence.
The repository has no security policy. This limits disclosure transparency, though it is secondary to the package being marked abandoned and inactive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version ~2.3|~3.0 | — | — |
erusev/parsedown Version ^1.6 | — | — |
erusev/parsedown-extra Version ^0.7.1 | — | — |
jeremyjumeau/parsedown-bundle Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.