The package includes a useful README, tests, an explicit MIT license, and no install-time scripts. Its small organization-backed project is not archived, but it lacks security scanning and has no recent development activity to support ongoing compatibility.
42%
Total Score
50
100
78
83
Only one release exists, published nearly seven years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained dependency despite its stable 1.0.0 version.
There were no commits and no active maintainers in the last three months, consistent with the repository's last push being nearly seven years ago. This materially increases abandonment and compatibility risk.
The repository has zero stars and forks and only one watcher, providing little community evidence or backup capacity. Popularity is supporting evidence rather than decisive on its own, so this is a moderate concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, while the long inactivity remains the larger concern.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a secondary concern for a small, inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^1.4 | — | — |
symfony/yaml Version ^4.3 | — | — |
symfony/config Version ^4.3 | — | — |
symfony/messenger Version ^4.3 | — | — |
symfony/http-kernel Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.