The source package is clearly documented, tested, licensed, and closely matched to its repository. Its small project footprint and lack of security policy leave limited oversight for future changes.
58%
Total Score
50
100
92
83
The package has had 6 releases since January 2017, but its latest release was in December 2020 and it has had no releases in the last 12 months. This is a substantial maintenance concern for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive since its last push in January 2023. The repository remains available, but recent maintenance capacity is not evident.
There were no new or closed issues or pull requests in the last month, while 5 issues and 3 pull requests remain open. This suggests unresolved maintenance demand, though the small project size limits how strongly it should be weighted.
The linked repository has no security policy. For a small, inactive package this limits the documented path for reporting and handling vulnerabilities, although it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~3.4|~4.3|~5.0 | — | — |
symfony/console Version ~3.4|~4.3|~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.