Usable with caveats: the source repository is active and backed by an organization, but the registry has had no release in over three years and all recent commits come from one contributor. The missing security policy adds a transparency gap for a framework dependency.
62%
Total Score
67
79
88
The package declares a proprietary license in its manifest, so it is not an unlicensed release. However, the proprietary terms may restrict use compared with a typical open-source dependency.
The package has 16 releases over more than seven years, but its latest registry release was over three years ago and there were no releases in the last 12 months. This raises maintenance and freshness concerns despite a previously regular release cadence.
All three recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe abandonment signal.
The repository recorded three commits in the last three months, indicating some ongoing maintenance. The low activity is modest rather than strong evidence of active development.
Composer is used as the build tool, providing expected package tooling, but no security scanning tools were detected. The missing scanning capability limits assurance around project maintenance practices.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
smarty/smarty Version ^4.1 | — | — |
symfony/console Version ^6.0|^5.0 | — | — |
symfony/var-dumper Version ^6.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.