The repository is small and offers no tests or security scanning, while its README contains no usable documentation. The MIT declaration and unarchived matching repository are positives, but they do not offset the lack of ongoing maintenance.
43%
Total Score
0
72
This package has made only one release, on April 20, 2024, with no releases in the last 12 months. That is strong evidence of limited maintenance for a framework dependency.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful development since the sole release over two years ago.
The package includes a README entry and a GitHub release for this version, but the README has zero characters and neither the package nor repository has tests or a changelog. The empty documentation is a real transparency gap for a framework consumers must integrate with.
The repository has zero stars and forks and one watcher, providing little supporting evidence of adoption or community resilience. Popularity is supporting evidence, so this reinforces but does not determine the abandonment concern.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.15 | — | — |
symfony/finder Version ^7.0 | — | — |
monolog/monolog Version ^3.5 | — | — |
symfony/console Version ^7.0 | — | — |
symfony/routing Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.