The package has a clear README, tests, a matching source repository, and an explicit license. Its lone alpha release leaves compatibility expectations unclear, while 17 runtime dependencies increase upgrade burden.
12%
Total Score
50
50
83
The registry marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because future fixes and support are not indicated.
The package has only one release, published more than nine years ago, with no releases in the last 12 months. This strongly indicates abandonment and leaves no maintained release path.
The linked repository is archived, even though it was pushed in January 2024. An archived source project is generally unfit for a new dependency because active maintenance is no longer expected.
The package declares 17 runtime dependencies, including several related packages, which increases compatibility and upgrade burden for an unmaintained release.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a secondary transparency gap beside the stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/yaml Version >=2.8.7 | — | — |
doctrine/cache Version ^1.6 | — | — |
symfony/config Version >=2.8.7 | — | — |
symfony/finder Version >=2.8.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.