Unfit to use for new projects: the package is abandoned on Packagist, its repository is archived, and it has had no release since June 2019. The MIT license and clear README do not offset the lack of ongoing maintenance.
18%
Total Score
0
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself indicates the package is no longer maintained.
The package has 138 historical releases, but none in the last 12 months and the latest release was in June 2019. Its long release gap strongly indicates abandonment despite its formerly active history.
There were zero commits and zero active maintainers during the last three months. This confirms that the project is not receiving current maintenance.
The linked source repository is archived, with its last push in January 2020. An archived repository indicates active maintenance has ended.
The linked repository name does not match the package name and its README does not mention the package, creating some uncertainty about the repository linkage. The organization backing provides context, but does not remove this transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ~2.3|~3.0 | — | — |
symfony/process Version ~2.3|~3.0 | — | — |
symfony/filesystem Version ~2.3|~3.0 | — | — |
symfony/http-kernel Version ~2.3|~3.0 | — | — |
symfony/class-loader Version ~2.3|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.