The package has a substantial README, comprehensive tests, and a clear BSD-3-Clause license. Its small audience, absent security scanning, and single publisher leave limited evidence of ongoing support.
45%
Total Score
0
67
50
The latest release was in March 2018, with no releases in the last 12 months and a package age of over 8 years. Nine historical releases show an initial release effort but do not offset the prolonged release silence.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with no observed development since March 2018. This is strong evidence of abandonment risk for a library dependency.
The repository has 2 stars, 0 forks, and 1 watcher, indicating a very small user and contributor footprint. Popularity is supporting evidence rather than a verdict, but it offers little evidence of community resilience.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools were detected. This weakens supply-chain transparency while the inactive project provides little evidence of compensating review.
The repository has no security policy. That limits the visible process for reporting and handling vulnerabilities, especially concerning for a dependency with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^3.4 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.