Tests, signed release notes, and a security policy provide useful project evidence. The archived codebase and lack of recent activity leave no dependable maintenance path for a new dependency.
12%
Total Score
50
50
67
Packagist marks the entire package as abandoned, with no replacement specified; this is a severe direct warning against taking a new dependency.
The package has 24 releases since December 2019, but it has had no releases in the last 12 months and the latest release was in March 2024, indicating abandonment risk.
The repository recorded zero commits and zero active maintainers over the last three months, strongly reinforcing the abandonment concerns from its archived and deprecated status.
The linked repository is archived, despite being pushed in November 2024; archived status means the project is no longer an active maintenance target.
A post-autoload-dump install-time script runs during dependency installation, adding execution complexity and a modest supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
symfony/flex Version ^1.3.1 | — | — |
symfony/mime Version * | — | — |
symfony/yaml Version * | — | — |
doctrine/dbal Version ^4.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.