The package is small and clearly identified, with a matching repository, README, MIT license, and no install-time scripts. Its long inactivity and lack of tests or security policy reduce confidence for a new dependency.
58%
Total Score
0
78
83
The latest release was in January 2023, with no releases in the following three years and eight months; this indicates a dormant maintenance cycle for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with several years of inactivity and increasing abandonment risk.
The repository has zero stars and forks and one watcher, offering little supporting evidence of external scrutiny; popularity is only a secondary concern because the package is small.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a package with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version 5.* | — | — |
doctrine/cache Version 2.* | — | — |
symfony/validator Version 5.* | — | — |
doctrine/annotations Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.