It includes a substantial codebase, documentation, tests, changelog, and a clear license. Maintenance and security oversight have effectively stopped, leaving new projects exposed to abandonment and compatibility risk.
15%
Total Score
33
50
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The last release was in January 2021, with no releases in the last 12 months. That is roughly 5 years and 8 months without a release and indicates abandonment risk.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the archived repository and extended release gap.
The linked repository is archived and was last pushed in January 2021, so it is no longer receiving normal project maintenance.
The package declares 28 runtime dependencies, including a broad framework and bundle stack. Combined with the long maintenance gap, this increases compatibility and update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
qafoo/rmf Version 1.0.* | — | — |
twig/twig Version ^1.0 | — | — |
doctrine/dbal Version 2.5.*@beta | — | — |
symfony/symfony Version ~2.7 | — | — |
kriswallsmith/buzz Version >=0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.