The project has one active contributor, and all four workflow actions are unpinned. MIT licensing, repository tests, a changelog, and no install scripts provide useful safeguards.
65%
Total Score
63
93
75
Only one registry account has publish access. Because the repository is owned by an individual rather than an organization, this leaves limited publishing redundancy.
The latest registry release was published nearly five years ago, with no releases in the last 12 months. The repository was pushed recently, which partly offsets the stale registry cadence but does not remove release uncertainty.
All recent repository commits came from one contributor, so maintenance depends entirely on that person despite the repository remaining active.
There was one commit in the last three months, showing some recent activity but at a very low maintenance pace alongside the long gap between releases.
The repository has no security policy, which is a transparency gap for reporting and handling vulnerabilities, though it is not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^3.4 || ^4.0 || ^5.0 || ^6.0 | — | — |
symfony/console Version ^3.4 || ^4.0 || ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.