Usable with caveats: the package is licensed, tested, documented, stable, and backed by a matching organization repository, but its last registry release was over eight years ago and there has been no recent commit activity. Depend on it only if its older Symfony support remains appropriate for your project.
58%
Total Score
75
100
83
90
There have been no releases in the last 12 months, and the latest registry release was on May 22, 2018. This long release gap is a significant maintenance concern for a framework integration package.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old package release, this points to limited current maintenance capacity.
There are no open issues, but there is one open pull request and no issues or pull requests were closed in the last month. This is consistent with low current project activity.
The repository has eight stars and three forks, indicating a small user base. Popularity is only supporting evidence, so this modest reach is a minor concern rather than a decisive risk.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency and maintenance gap, though it is less severe because the repository has no analyzed workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.8|~3.0|~4.0 | — | — |
symfony/validator Version ~2.8|~3.0|~4.0 | — | — |
symfony/http-kernel Version ~2.8|~3.0|~4.0 | — | — |
doctrine/annotations Version ~1.0 | — | — |
symfony/dependency-injection Version ~2.8|~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.