The MIT license, README, tests, and matching source repository provide a clear, inspectable project structure. Composer build support is present, but there is no security scanning and the small project has limited operational support.
52%
Total Score
33
100
83
88
There were no commits and no active maintainers in the last 3 months. Combined with the single old release, this is the clearest sign that maintenance may have stalled.
The repository is owned by a user account rather than an organization, so there is no visible organizational backing to offset the limited recent activity.
The package has only one release, published about 6 years ago, with no releases in the last 12 months. That makes ongoing maintenance and compatibility uncertain.
There are no open issues but one open pull request, with no issues or pull requests merged in the last month. This offers little evidence of active community maintenance.
The repository has 2 stars and no forks, indicating limited external adoption. Popularity is only supporting evidence, so this modestly lowers confidence in project maturity rather than deciding the verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^1.3.1 | — | — |
symfony/yaml Version 5.0.* | — | — |
symfony/dotenv Version 5.0.* | — | — |
symfony/console Version 5.0.* | — | — |
symfony/framework-bundle Version 5.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.