Clear licensing, thorough tests, and release notes improve day-to-day confidence. Maintenance evidence is extremely old, with no recent releases or commits, and the repository has no security policy or scanning.
45%
Total Score
0
100
67
75
The package has had no releases in the last 12 months, and its latest release was about 10 years ago. Its 12 historical releases show an earlier active period but do not offset the prolonged silence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release hiatus and indicating substantial abandonment risk.
Composer build tooling is present, but no security-scanning tools were detected. The build setup supports reproducibility, while the missing scanning coverage is a modest hygiene gap.
The repository is not marked archived, which is a small positive, but its last push was about 10 years ago and therefore does not demonstrate current maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is secondary to the much stronger evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.