Usable with caveats: it is licensed, tested, stable, and backed by an organization, but maintenance has slowed substantially. There have been no commits in the last three months and only one release in the last 12 months, with no security policy or scanning configured.
62%
Total Score
75
50
83
83
Seven runtime dependencies, including Symfony components and a final-class testing utility, create a moderate dependency surface but do not by themselves indicate an unhealthy package.
The package has four releases over about 2 years and 2 months, but only one release in the last 12 months with a median interval of about 147 days. This suggests a slow maintenance pace rather than active development.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with only one release in the last 12 months, this is a meaningful sign of slowed maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of a broad user or contributor community.
The repository uses Make and Composer, but has no detected security-scanning tools. The build tooling is a positive, while the missing scanning reduces supply-chain transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/string Version ^7.3 | — | — |
dg/bypass-finals Version ^1.8 | — | — |
symfony/validator Version ^7.3 | — | — |
jetbrains/phpstorm-attributes Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.