The project has seen no commits for over nine years and only two releases, leaving substantial abandonment risk. A clear license, README, and test suite provide useful transparency, but no security policy or scanning is present.
40%
Total Score
25
50
71
83
The package has only two releases, with the latest in October 2016 and none in the last 12 months, indicating a long-standing lack of release maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the last push being over nine years ago and creating substantial abandonment risk.
The package declares 11 runtime dependencies, including several Symfony and Doctrine components, creating a relatively broad maintenance surface for an otherwise inactive package.
There were no new or closed issues or pull requests in the last month. This is consistent with the inactive repository, though the lack of open work avoids an additional maintenance concern.
The repository has zero stars and forks and only one watcher, so there is little visible community support to compensate for the inactive maintainer activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.5 | — | — |
doctrine/orm Version >=2.3 | — | — |
symfony/finder Version ~2.3 | — | — |
twig/extensions Version ~1.0 | — | — |
symfony/filesystem Version ~2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.