The release is clearly licensed, has a readable package and tested source repository, and uses no install-time scripts. Its project backing remains identifiable, but the package is no longer maintained and the registry marks it abandoned; use the listed replacement instead.
18%
Total Score
50
58
100
Packagist marks the entire package abandoned and points to php-di/symfony-bridge as its replacement. This is a direct warning against taking a new dependency on this package.
The latest release was in March 2018, with no releases in the last 12 months despite nine releases historically. That long release gap strongly indicates abandonment risk.
The repository had zero commits and zero active maintainers in the last three months. Together with the old latest release, this shows no current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with one issue still open. This supports the conclusion that the project is inactive.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, it makes package-to-repository ownership less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ~6.0 | — | — |
symfony/config Version ~3.3||~4.0 | — | — |
symfony/http-kernel Version ~3.3||~4.0 | — | — |
symfony/dependency-injection Version ~3.3||~4.0 | — | — |
symfony/proxy-manager-bridge Version ~3.3||~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.