Risky to adopt: the package has received no release or repository commit activity for about 11 years. It remains licensed, documented, tested, and not deprecated or archived, but its long abandonment gap and minimal project traction make ongoing compatibility and maintenance a liability.
42%
Total Score
50
50
72
90
The latest release was published in July 2015, with no releases in the last 12 months, indicating roughly 11 years without a new registry release. The seven-release history shows the project once had activity, but not enough to offset the prolonged current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. This is strong evidence that fixes and compatibility updates are unlikely to arrive.
The package declares four runtime dependencies, including PHP, Symfony, Doctrine Cache, and Guzzle. This is a moderate dependency surface rather than an unusually broad one, though the age of those integrations may create compatibility concerns.
The repository has only 1 star, 2 forks, and 2 watchers, providing little supporting evidence of a broad community that could sustain the project. Low popularity alone is not decisive, but it reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This limits automated security oversight, while the existing build tooling provides a small compensating positive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzle/guzzle Version ~3.0 | — | — |
doctrine/cache Version ~1.3 | — | — |
symfony/framework-bundle Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.