A clear MIT license, matching repository, and usable README make the package easy to inspect. Its small codebase has no tests or security tooling, leaving compatibility and maintenance risks unverified.
35%
Total Score
33
100
72
83
This is the only release, published about 11 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a package intended for ongoing framework integration.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was about 11 years ago. This is the clearest maintenance and abandonment concern.
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it offers less visible backing for a package that has had no activity for about 11 years.
There are three open issues but no new or closed issues and no pull-request activity in the last month. The unresolved, inactive issue state adds modest evidence that maintenance has stopped.
The repository has 28 stars and one fork, providing limited evidence of use or visibility. Popularity is too low to compensate for the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.0 | — | — |
symfony/templating Version ~2.0 | — | — |
symfony/http-kernel Version ~2.0 | — | — |
reactjs/react-php-v8js Version dev-master | — | — |
symfony/dependency-injection Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.