The MIT declaration and substantial source tree provide useful baseline transparency, while 45 runtime dependencies increase upgrade and compatibility burden. The registry and repository show no release or commit activity for nearly seven years, making abandonment the main adoption risk.
35%
Total Score
0
50
75
88
The package has 56 releases but none in the last 12 months, with the latest release in December 2019; this is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The package declares 45 runtime dependencies, including many framework and extension requirements, creating a substantial compatibility and maintenance burden for adopters.
The repository name matches the package, but its README does not mention the package, leaving the package-to-source relationship less clearly documented than expected.
Composer build tooling is present, supporting reproducible project structure, but no security-scanning tooling was detected; this is a minor transparency gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sdk Version ^2.0.0 | — | — |
symfony/form Version ^4.4 | — | — |
symfony/lock Version ^4.4 | — | — |
symfony/yaml Version ^4.4 | — | — |
cocur/slugify Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.