Tests and a matching repository provide useful traceability, while minimal adoption and no security policy leave little evidence of ongoing support. Pinning 2.1.0 is prudent only if you can maintain or replace it.
35%
Total Score
33
50
72
75
The package has 17 releases, but none in the last 12 months and the latest release was in February 2022, roughly four years ago. That strongly raises abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years. This is strong evidence of limited ongoing support.
Eleven runtime dependencies, including several Symfony and security components, create a meaningful dependency-upkeep surface for a package that has not released recently.
The manifest declares the package proprietary, and no license file was detected in the artifact or repository. This limits open-source reuse and transparency despite being an explicit licensing choice.
Only one registry account has publish access, leaving a thin publishing base. This is a modest risk because the repository owner is also identified as an individual rather than an organization.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^4.0|^5.0 | — | — |
doctrine/common Version * | — | — |
symfony/console Version ^4.0|^5.0 | — | — |
symfony/routing Version ^4.0|^5.0 | — | — |
symfony/http-kernel Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.