Usable with caveats: it is licensed, has tests and a useful README, and is not deprecated or archived. Recent repository activity has stopped, popularity is very low, and the reported latest version conflicts with the assessed release, so verify maintenance before adopting it.
62%
Total Score
50
100
78
100
The registry namespace and repository owner match, supporting package ownership continuity; the owner is an individual account rather than an organization, so there is limited backing evidence.
The package has existed since January 2019 with 20 releases and a release as recent as February 2026, but only one release in the last 12 months indicates a slow current cadence.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that current maintenance has paused or slowed substantially.
The repository has only 2 stars and no forks or watchers, providing little community evidence or external support. Popularity is supporting evidence rather than a decisive health measure.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version ^3.4.40 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.