The MIT license, README, tests, and matching source make integration straightforward. The package is not deprecated or archived, but its metadata is inconsistent and security coverage is limited.
38%
Total Score
0
71
83
The last release was in June 2016, and there were no releases in the past 12 months despite the package being over 10 years old. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the past 3 months, and its last push was in July 2017. This reinforces the abandonment concern rather than showing active support.
Composer is used for the build, but no security scanning tools are configured. That leaves fewer visible safeguards for dependency and build maintenance.
The repository has no security policy. This is a transparency and maintenance gap, although it is less significant than the lack of release and commit activity.
The assessed release is v2.0.3, while the registry reports v1.0.0 as the latest version. That inconsistency makes the release history and version status difficult to trust.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.11|~2.0 | — | — |
php-tmdb/api Version dev-feature/guzzle-6 | — | — |
symfony/config Version >=2.3,<4 | — | — |
symfony/http-kernel Version >=2.3,<4 | — | — |
symfony/event-dispatcher Version >=2.3,<4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.