The small codebase has a clear MIT license and no install-time scripts. Its lone maintainer, absent security tooling, and minimal adoption leave little evidence of long-term support.
54%
Total Score
50
79
83
One registry maintainer is consistent with a small user-owned project, but it leaves limited visible capacity for continuity or review if that person becomes inactive.
The package has only one release, published about 3 years and 11 months ago, with no releases in the last 12 months. This limits evidence of maintained compatibility.
The repository recorded no commits and no active maintainers in the last three months. A push in December 2025 shows the repository is not archived, but recent development activity remains unproven.
The repository name matches the package, which supports the linkage, but the README does not mention the package. That weakens documentation and ownership clarity slightly.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/messenger Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.