Its stable 1.0.2 release and matching repository make adoption straightforward. The small, inactive project has little evidence of ongoing support, and no security policy or scanning is present. Pin this version only if its limited maintenance risk is acceptable.
43%
Total Score
0
75
50
The package has only three releases, with none in the last five years and the latest published in August 2021. This is strong evidence of abandonment risk for a framework integration.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating no current maintenance.
The repository has one star and no forks, providing little evidence of broad community review or support. Popularity is supporting evidence rather than decisive on its own, but it reinforces the maintenance concern.
The project uses Composer but has no detected security scanning tools. The build tooling is appropriate, while the missing scanning reduces supply-chain and dependency hygiene.
No security policy is present in the repository, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less serious than the maintenance signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^4.4 || ^5.0 | — | — |
symfony/validator Version ^4.4 || ^5.0 | — | — |
symfony/http-kernel Version ^4.4 || ^5.0 | — | — |
doctrine/annotations Version ^1.10 | — | — |
symfony/expression-language Version ^4.4 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.