Risky to adopt: the package has had no release or repository activity since 2018, making abandonment and compatibility concerns substantial. It is licensed, documented, tested, and clearly backed by the matching organization repository, but those strengths do not offset the prolonged inactivity.
38%
Total Score
50
71
The package has 39 releases since 2016, but none in the last 12 months and the latest release was about 8 years ago. This long release hiatus is a strong abandonment and compatibility concern.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's multi-year release hiatus. This materially lowers confidence in ongoing maintenance.
The repository uses Composer for builds, providing basic build transparency, but it has no security scanning tools. This is a secondary hygiene gap beside the much larger inactivity concern.
The repository is not marked archived, which avoids the strongest abandonment signal, but it was last pushed about 8 years ago. Its unarchived status does not compensate for the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^3.2 | — | — |
symfony/validator Version ^3.2 | — | — |
symfony/templating Version ^3.2 | — | — |
composer/installers Version ~1.0 | — | — |
doctrine/annotations Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.