The package is licensed, has a matching source tree, and is backed by an organization. Its missing security policy and absent package mention in the README reduce transparency, though the small package structure is understandable.
38%
Total Score
50
60
50
The package has had no release in about 9 years, with only four releases overall. That long publishing gap is strong evidence that maintenance has stopped.
The repository has recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving current maintenance unverified.
The repository name matches the package, but its README does not mention the package, leaving some uncertainty about how clearly the source documents this distribution.
Composer is used for the build, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence of abandonment by itself.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.15||^2.0 | — | — |
symfony/config Version ~2.8|~3.0 | — | — |
symfony/finder Version ~2.8|~3.0 | — | — |
symfony/console Version ~2.8|~3.0 | — | — |
symfony/http-kernel Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.