The MIT license, README, and matching organization-owned repository provide clear provenance and basic consumer guidance. Its broad dependency set has no visible security scanning or policy, and the project offers little ongoing support for a new API skeleton. Pinning this release would leave maintenance and compatibility risks with the adopter.
38%
Total Score
50
75
50
This package has only one release, published over 8 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency intended for current projects.
The repository has recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no updates since April 2018. The unarchived status does not compensate for the lack of observed activity.
There is one open issue and no new or closed issues or pull requests in the last month. This is supporting evidence of inactivity, though the small project size limits how much can be inferred from issue volume alone.
The linked repository has no security policy. For an API project with 17 runtime dependencies, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lts Version ^4@dev | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/yaml Version ^4.0 | — | — |
symfony/console Version ^4.0 | — | — |
symfony/orm-pack Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.