The project has had no release or commit activity for over 10 years, with issues and pull requests also inactive. Its license, documentation, tests, release notes, and organization-backed repository are solid, but they do not offset the abandonment risk.
38%
Total Score
50
75
50
The latest release was published over 10 years ago, and there were no releases in the last 12 months. The package had a reasonable earlier cadence, but the prolonged release gap is a major abandonment concern.
The repository recorded zero commits and zero active maintainers over the last 3 months, consistent with the long release gap and indicating no visible current maintenance.
There were no new or closed issues and no merged pull requests in the last month, so the repository shows no recent evidence of issue handling or development activity.
The linked repository is not marked archived, which is a positive ownership signal, but its last push was over 10 years ago and does not overcome the inactivity evidence.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This compounds the maintenance concern, although it is less significant than the absence of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/yaml Version ^2.7 | — | — |
symfony/debug Version ^2.7 | — | — |
symfony/config Version ^2.7 | — | — |
symfony/finder Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.