Security documentation is absent, and both CI action references are unpinned. The package still includes tests, a substantial README, and a license, but ongoing support is uncertain.
57%
Total Score
75
88
50
The package has 48 releases since March 2014, but none in the last 12 months and its latest release was over 4 years ago, indicating likely stagnation.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the evidence of stalled maintenance.
The project uses Make and Composer for build tasks, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
No security policy was found in the repository, making vulnerability reporting and response expectations unclear.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned; this is a hygiene risk rather than a severe workflow threat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~4.4 || ~5.0 || ~6.0 | — | — |
predis/predis Version ^1.1.8 | — | — |
symfony/cache Version ~4.4 || ~5.0 || ~6.0 | — | — |
doctrine/cache Version ~1.3 | — | — |
symfony/config Version ~4.4 || ~5.0 || ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.