The source remains available, matches the package, and includes a README, tests, and an MIT license. However, its small community and absent security policy provide little reassurance for a dependency with no recent maintenance.
15%
Total Score
50
67
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk even though the repository remains available.
The latest release was published in July 2013, over 13 years ago, and there have been no releases in the last 12 months. This strongly indicates the package is no longer maintained for current consumers.
The repository had no commits and no active maintainers in the last 3 months. Although it was pushed in September 2022, current inactivity increases abandonment risk.
The repository has no security policy. That weakens vulnerability-reporting transparency, especially for a dependency with no recent release activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version >=1.4,<2.0 | — | — |
symfony/config Version ~2.1 | — | — |
symfony/finder Version ~2.1 | — | — |
symfony/http-kernel Version ~2.1 | — | — |
kriswallsmith/assetic Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.