Risky to depend on: this release has not been updated since August 2023, with only one published version and no recent repository commits. It has tests, a readable project, and a non-archived matching repository, but the prolonged inactivity makes maintenance uncertain.
42%
Total Score
0
75
80
This is the package's only release, published about 3 years ago, with no releases in the last 12 months. That limited history and prolonged release gap materially increase abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap. This is the strongest evidence that ongoing maintenance is not demonstrated.
The package defines post-install and post-update scripts, which add execution during dependency operations. This is a supply-chain exposure to review, though the signal alone does not show that the scripts are harmful.
The repository uses Make and Composer, demonstrating basic build tooling, but it has no detected security scanning tools. That is a modest hygiene gap rather than evidence of abandonment on its own.
No security policy was found, leaving vulnerability reporting and disclosure practices unspecified. For a referral system handling user and event data, this is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.15 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version 6.3.* | — | — |
symfony/dotenv Version 6.3.* | — | — |
symfony/console Version 6.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.