The package includes a clear README and extensive tests, making its behavior easier to assess. Its source and dependency ecosystem appear dated, so future compatibility and maintenance support are uncertain.
38%
Total Score
72
75
The latest release was published in January 2014, with no releases in the last 12 months and only four releases overall. This prolonged inactivity is strong evidence of abandonment risk.
The repository has one star and no forks, offering little supporting evidence of a broad user or contributor base. Popularity is only supporting evidence, so this reinforces rather than determines the abandonment concern.
The project uses Composer for builds, but no security scanning tooling is reported. This is a modest transparency gap in an otherwise very old project.
The linked repository is not archived, which preserves the possibility of maintenance, although its last push was in November 2014 and does not offset the long release gap.
The repository has no security policy. That limits the documented path for reporting vulnerabilities, though it is secondary to the much larger maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.15 | — | — |
symfony/yaml Version ~2.4 | — | — |
sebastian/diff Version ~1.1 | — | — |
symfony/config Version ~2.4 | — | — |
symfony/finder Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.