Unfit to use for a new dependency: the package is marked abandoned, its repository is archived, and it has had no releases for nearly seven years. Its MIT license, tests, release notes, and organization backing are positives, but they do not offset the lack of ongoing maintenance.
18%
Total Score
50
63
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the release is no longer presented as an actively supported dependency.
The package has 40 releases, but the latest release was in October 2019 and there were no releases in the last 12 months. The long release gap materially increases abandonment and compatibility risk.
The repository recorded no commits and no active maintainers during the last three months. This confirms that the maintenance gap is current rather than merely an irregular release schedule.
The linked Sonata repository is archived, and its last push was in October 2021. Archived source indicates the project is no longer maintained, despite the repository belonging to the owning organization.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^2.8.8 || ^3.2 || ^4.0 | — | — |
symfony/config Version ^2.8 || ^3.2 || ^4.0 | — | — |
symfony/finder Version ^2.8 || ^3.2 || ^4.0 | — | — |
doctrine/phpcr-odm Version ^1.4.2 || ^2.0 | — | — |
symfony/http-kernel Version ^2.8 || ^3.2 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.