The package has a clear license, readable documentation, tests, and organizational ownership. Its prerelease status and very old maintenance record make long-term support uncertain, especially for a production dependency.
44%
Total Score
50
71
75
The latest release was about 8 years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a package being considered today.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release inactivity. The repository is not archived, but that does not compensate for the absence of recent work.
The repository has 5 stars and no forks, providing little supporting evidence of broad community adoption or an active external maintenance base. Popularity is only supporting evidence, so this does not decide the result alone.
The repository has no security policy. This is a transparency and maintenance gap, although it is less decisive than the much older release and commit history.
The assessed version is a prerelease beta, and one-third of recent releases were prereleases. That adds compatibility and support uncertainty on top of the long release gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.8|~3.0 | — | — |
symfony/finder Version ~2.8|~3.0 | — | — |
twig/extensions Version ~1.0 | — | — |
symfony/templating Version ~2.8|~3.1 | — | — |
symfony/http-kernel Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.