The package has a clear README, tests, matching source repository, and MIT licensing. Its missing security policy and minimal popularity add modest concern, but the long absence of maintenance is the main problem.
38%
Total Score
100
100
72
75
Only two releases exist, and none were published in the last 12 months; the latest release is nearly 13 years old. This is strong evidence of abandonment risk for a maintained Symfony integration library.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very low figures provide no external adoption signal to offset the stagnation.
Composer build tooling is present, but no security scanning tooling is reported. This is a minor hygiene gap rather than a standalone dependency risk.
The repository is not archived, which is a compensating positive, but its last push was in December 2013. The untouched repository still indicates severe maintenance stagnation.
The repository has no security policy. This is a transparency and incident-handling gap, though it is secondary to the much older maintenance record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moaction/jsonrpc-client Version ~1.4 | — | — |
moaction/jsonrpc-server Version ~1.1 | — | — |
symfony/framework-bundle Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.