The repository contains tests, matches the package, and has no install-time scripts or workflow findings. Its small audience and lack of security scanning leave little evidence of ongoing oversight.
35%
Total Score
75
50
63
83
Only two releases were published, both in March 2017, with no release in more than 9 years. This is strong evidence of abandonment risk for a dependency.
The package declares seven runtime dependencies for a small Symfony bundle, including framework components and a related notification package. This adds maintenance coupling, especially for an unmaintained release.
There are no open issues or pull requests and no recent activity. While a quiet issue tracker is not inherently harmful, here it reinforces the long period without maintenance evidence.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of community review or shared maintenance capacity.
Composer is used for builds, but no security scanning tools are present. This is a modest oversight gap, not proof of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version >=3.1 | — | — |
symfony/http-kernel Version >=3.1 | — | — |
symfony/event-dispatcher Version >=3.1 | — | — |
symfony/options-resolver Version >=3.1 | — | — |
php-solution/notification Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.