Risky to adopt: the last release was about 10 years ago and the repository has had no commits or active maintainers for over 10 years. It is licensed and has tests, but the package also appears weakly connected to its linked repository and lacks a security policy.
38%
Total Score
0
63
75
Only two releases exist, with the latest published about 10 years ago and no releases in the last 12 months. This strongly indicates abandonment risk for a Symfony integration package.
The repository recorded zero commits and zero active maintainers in the last three months, with the last push also about 10 years ago. The old code may still work, but there is no observed maintenance capacity.
The repository name does not match the package name, and its README does not mention this package. That weakens confidence that the linked repository is the package's actual project home.
No security policy was found. This is a transparency gap, although the package is small and has no observed workflow-based risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.