Its simple seven-file layout and declared GPL license are clear, but repository linkage is weak and no security policy is present. Pinning this old resource bundle would carry substantial compatibility and abandonment risk.
34%
Total Score
0
50
83
The package has only one release, published over 13 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in July 2013. The long-standing lack of activity is not offset by the repository merely remaining available.
The repository name does not match the package name and its README does not mention the package, so the link between the registry artifact and source project is not clearly established.
The repository has no security policy. This is a transparency gap, although the package is a small seven-file resource bundle with no recent activity or reported workflow exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version >=2.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.