The package has a focused file tree, tests, a README, an MIT declaration, and no install-time scripts. Its small dependency set and matching source repository help, but limited security tooling leaves future maintenance less transparent.
48%
Total Score
0
100
75
50
Only two releases were published, with the latest on May 25, 2021 and none in roughly five years. This strongly raises abandonment risk despite the package having reached a stable 1.0.2 release.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance concern, not a severe risk by itself.
The linked repository has no security policy. For a small bundle this is a documentation gap, but it adds uncertainty about how future vulnerabilities would be handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~4|~5 | — | — |
symfony/string Version ^4.0 || ^5.0 | — | — |
symfony/http-kernel Version ^4.0 || ^5.0 | — | — |
symfony/dependency-injection Version ^3.4 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.