Collection Library
42%
Total Score
unhealthy
Risky: no releases or repository activity since March 2019.
The package has had no release in over 7 years: its latest release was March 8, 2019, despite 11 releases overall. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap and providing no evidence of current maintenance.
Only one account has registry publishing access. The organization-owned project makes a short registry maintainer list less concerning, but it still leaves limited visible publishing capacity.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of an active user or contributor community.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. That is a transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version 4.2.0-BETA2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.