The linked project has no security policy or security scanning, and its README does not identify this package. MIT licensing, substantial documentation, repository tests, a changelog, and release notes provide useful transparency.
43%
Total Score
67
100
69
83
The package has 87 releases, but none in the last six years; the latest release was in January 2020. This long period without a release materially raises abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating that maintenance has effectively stopped.
The repository name does not match the package name and its README does not mention the package. That raises concern that the linked source may not clearly belong to this package.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these figures provide no visible community backing to offset inactivity.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and hygiene gap for a package with a substantial dependency and build surface.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/asset Version ^3.4|^4.2|^5.0 | — | — |
prolix/imagine Version 1.2.* | — | — |
symfony/finder Version ^3.4|^4.2|^5.0 | — | — |
symfony/process Version ^3.4|^4.2|^5.0 | — | — |
symfony/filesystem Version ^3.4|^4.2|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.