The repository remains active enough to contain tests, release notes, and a valid MIT license, but it has no recent commits or issue activity. Three workflow actions are unpinned, adding a smaller maintenance risk.
22%
Total Score
67
63
67
The package explicitly borrows the identity of the much more established rollbar/rollbar package, with a different owner indicated by the signal. Although artifact overlap is only 0.2, this naming pattern creates a serious risk that consumers select the wrong package.
Packagist marks the entire package as abandoned, with no effective replacement identified. Package-level deprecation is a severe adoption risk even though the repository is not archived.
The latest release was published in February 2020, more than six years before this assessment, and there were no releases in the preceding 12 months. The nine-release history shows the package was once maintained but is now stale.
The repository recorded zero commits and zero active maintainers in the last three months. Its last push was in April 2024, so the source is not archived but current maintenance capacity is unclear.
There were no new or closed issues or pull requests in the last month, while eight issues and five pull requests remain open. This suggests little recent project attention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.0 | — | — |
rollbar/rollbar Version ^2 | — | — |
symfony/serializer Version * | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/monolog-bundle Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.