Tests, a clear MIT license, and a small dependency set make the package straightforward to inspect and integrate. Its long-term maintenance outlook is weak, so pinning this release carries ongoing compatibility and support risk.
38%
Total Score
25
100
75
75
The package has had only two releases, both in May 2018, and none in the last eight years. This is strong evidence of abandonment risk for a maintained dependency.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful repository activity since 2018. This materially increases abandonment risk.
Only one account has registry publish access. Because the repository is owned by an individual rather than an organization, this indicates a thin maintainer base and limited continuity.
Composer is used as the build tool, but no security scanning tooling is present. The missing scanning is a hygiene concern, though it is less significant than the maintenance evidence.
The repository is not archived, but it was last pushed in May 2018. The non-archived status provides little compensation for the prolonged lack of activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ~2.3|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.