The package is clearly identified and licensed, with a readable artifact and stable version. Its maintenance has stopped, the repository is archived, and the registry marks the package abandoned; choose an actively maintained alternative.
12%
Total Score
50
50
88
The package borrows the identity of knplabs/knp-menu, a much more established package, and explicitly has borrows_lookalike_identity set to true. Consumers may select this package when they intended the lookalike.
Packagist marks the entire package abandoned, with no replacement provided. This is a severe adoption risk because future fixes and compatibility work are not expected.
The latest release was about 8 years ago, with no releases in the last 12 months. The long gap strongly indicates abandonment rather than merely a slow release cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Together with the archived status and stale release history, this shows no current maintenance capacity.
The linked repository is archived, and its last push was about 4 years ago. An archived source project is not a dependable basis for a new dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~3.0 | ~4.0 | — | — |
doctrine/common Version ~2.4 | — | — |
symfony/http-kernel Version ~3.0 | ~4.0 | — | — |
symfony/security-core Version ~3.0 | ~4.0 | — | — |
symfony/dependency-injection Version ~3.0 | ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.