Tests, documentation, and release notes make the package understandable, while its small dependency set keeps adoption straightforward. Registry access is held by one person and the repository has no security scanning, limiting visible maintenance safeguards.
58%
Total Score
50
100
75
75
The package has only two releases, with the latest published nearly 13 years ago and none in the last 12 months. This is strong evidence of stagnation for a library that may need compatibility fixes.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this indicates little current capacity for fixes.
Registry publishing access is held by one person, and the repository owner is an individual rather than an organization. That leaves a thin visible maintainer base if the project needs renewed work.
There were no new or closed issues or pull requests in the last month, while two issues and two pull requests remain open. This suggests limited recent project activity.
Composer is used for the build, but no security scanning tools are present. This is a maintenance and transparency gap, though not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version >=2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.