The MIT license, matching repository, tests, and release notes improve transparency. Its small scope and four runtime dependencies are straightforward, but future compatibility and fixes are uncertain.
38%
Total Score
0
75
50
The package has had only 3 releases, all concentrated on 15 March 2017, with no release in the last 12 months. This long period without published updates is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's lack of releases since March 2017. No provided maintenance signal compensates for this inactivity.
Composer is used as a build tool, but no security scanning tooling is present. This is a modest hygiene gap that adds uncertainty to maintenance, though it is less significant than the prolonged inactivity.
The repository has no security policy, leaving no documented route for reporting vulnerabilities. This lowers transparency, but it is secondary to the much stronger abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.2 | — | — |
symfony/event-dispatcher Version ^3.2 | — | — |
nsrosenqvist/blade-compiler Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.