A large dependency surface adds upgrade work, while tests and release notes improve traceability. The repository is active enough to remain credible, but recent release and commit activity are absent and workflow references are unpinned.
62%
Total Score
50
50
94
50
No commits and no active maintainers were recorded in the last three months, materially increasing abandonment and compatibility risk for a package whose latest registry release is also old.
Twenty-two runtime dependencies, including framework, HTTP, cache, and external API integrations, create a relatively large upgrade and compatibility surface for a package of this kind.
Composer post-install and post-update scripts add installation behavior that consumers should account for, but their presence alone is not evidence of poor maintenance or unsafe dependency use.
The project has a long history with 29 releases, but it has had no registry release in roughly three years, which lowers confidence in current maintenance.
There were no new or closed issues or pull requests in the last month, while 14 issues and 26 pull requests remain open; this suggests limited recent project attention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
badges/poser Version ^2.3.1 | — | — |
symfony/flex Version ^2.2 | — | — |
symfony/yaml Version ^6.1 | — | — |
predis/predis Version ^1.1 | — | — |
symfony/asset Version ^6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.