The package is clearly licensed and its repository matches the package, while installation runs no lifecycle scripts. There are no tests or security-scanning tools, which increases the risk of relying on such an old release.
38%
Total Score
0
67
75
Only two releases exist, with the latest published nearly 9 years ago and none in the last 12 months. This is strong evidence of an abandoned release line.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and indicating little current maintenance capacity.
The repository has zero stars and forks and only two watchers. Popularity is not decisive, but these very low adoption signals provide little evidence of a maintained community around the package.
Composer and Box provide build tooling, but no security-scanning tools are present. For a project with no recent maintenance, that is a meaningful hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This adds transparency risk, although it is less significant than the lack of maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.1 | — | — |
symfony/config Version ^3.2 | — | — |
symfony/finder Version ^3.2 | — | — |
symfony/console Version 3.0.* | — | — |
smalot/online-api Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.