Usable with caveats: the package is mature, licensed, documented, tested, and backed by an organization, but maintenance appears stalled. There have been no releases or repository commits for about three years, with unresolved issues and pull requests still open.
58%
Total Score
50
50
81
83
The repository recorded zero commits and zero active maintainers in the last three months, indicating that maintenance has effectively stalled recently.
The package has 16 runtime dependencies, including Symfony, Doctrine, Elasticsearch, and related libraries. This is a meaningful integration surface but not, by itself, evidence that the package is unsafe to depend on.
The package has 91 releases over roughly 12 years, but the latest recorded release was about three years ago and there were no releases in the last 12 months. This indicates a mature project with currently stalled release activity.
There were no new or closed issues or pull requests in the last month, while 41 issues and 17 pull requests remain open. This supports a concern about inactive maintenance.
Composer is used for builds, but no security scanning tooling was detected. The missing scanning is a modest transparency gap, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^4.4|^5.0 | — | — |
doctrine/cache Version ^1.7 | — | — |
symfony/finder Version ^4.4|^5.0 | — | — |
monolog/monolog Version ^1.24 | — | — |
symfony/console Version ^4.4|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.