The clear README, release notes, MIT licensing, and organization ownership provide useful transparency. However, maintenance has effectively stopped, leaving compatibility and support uncertain for a new Symfony project.
42%
Total Score
50
75
50
The package has 28 releases but none in the last 12 months, and its latest release was nearly five years ago. This is strong evidence of abandonment risk despite a previously regular release cadence.
There were zero commits and zero active maintainers in the last three months, consistent with the nearly five-year-old latest release. This substantially raises abandonment and compatibility risk.
post-install-cmd and post-update-cmd scripts run during dependency operations, adding installation complexity and execution surface. No provided signal shows that these scripts are harmful, so this is a moderate hygiene concern rather than a severe risk.
The repository has eight open issues and no issue or pull request activity in the last month, with no merged pull requests. The unresolved backlog reinforces the evidence of inactive maintenance.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene gap, though it is less important than the demonstrated maintenance stoppage.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^2.7.0|^3.0.6|^4.0|^5.0|^6.0 | — | — |
symfony/http-kernel Version ^2.7.0|^3.0.6|^4.0|^5.0|^6.0 | — | — |
limenius/react-renderer Version ^5.0.0 | — | — |
symfony/dependency-injection Version ^2.7.0|^3.0.6|^4.0|^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.