The package has clear licensing, a readable package, release notes, and a security policy. Its source is not archived, but the available evidence does not show strong ongoing ownership or maintenance capacity.
46%
Total Score
50
81
100
Although the package has 140 releases over about 13 months, only one release occurred in the last 12 months and the latest release is about 12 months old, indicating sharply reduced release activity.
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package, so the source may not clearly belong to this release.
Composer is used for the build, providing basic ecosystem-appropriate packaging support. No security scanning tooling was detected, which is a modest transparency gap but not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.3|~3.0 | — | — |
symfony/process Version ~2.3|~3.0 | — | — |
symfony/filesystem Version ~2.3|~3.0 | — | — |
symfony/http-kernel Version ~2.3|~3.0 | — | — |
symfony/class-loader Version ~2.3|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.