The MIT license and compact package structure make the release straightforward to inspect and use. Its source project lacks security and testing support, and the repository does not clearly identify this package, increasing adoption risk.
38%
Total Score
25
100
69
83
There have been six releases since September 2016, but the latest was in September 2017 and there were no releases in the last 12 months, indicating prolonged abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly nine years since the last release and indicating substantial abandonment risk.
There are no open issues or pull requests and no issue or pull-request activity in the last month, providing no evidence of an active maintenance channel.
The repository name does not match the package name and its README does not mention the package, so the link between the registry release and its source is less clear.
Composer build tooling is present, but no security scanning tooling was detected. This is a moderate hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.7 | ^3.0 | — | — |
symfony/validator Version ~2.7 | ^3.0 | — | — |
captioning/captioning Version ~2.4 | — | — |
symfony/http-foundation Version ~2.7 | ^3.0 | — | — |
symfony/dependency-injection Version ~2.7 | ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.