Install-time Composer hooks add operational exposure, and the repository has no security scanning. The MIT license, tests, release notes, and matching repository improve transparency but do not offset the maintenance concerns.
10%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement package provided. That is a severe dependency-maintenance risk.
This is the only registry release, published about 8 years ago, with no releases in the last 12 months. That provides strong evidence of abandonment.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with its archived state, this confirms that maintenance activity has stopped.
The linked repository is archived and was last pushed about 7 years ago. Archived source is a strong indication that fixes and maintenance are no longer expected.
The package defines post-install and post-update Composer scripts. These increase installation-time behavior and deserve review before adoption, although the signal alone does not establish a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lts Version ^4@dev | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/yaml Version ^4.0 | — | — |
symfony/asset Version ^4.0 | — | — |
symfony/dotenv Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.