Unfit to use: Packagist marks the package abandoned, and it has had no releases or repository commits since January 2023. The repository is intact and the release is documented, but those positives do not offset the clear abandonment risk.
22%
Total Score
0
57
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe warning against taking a dependency on this release.
The package has only two releases, both published in January 2023, with no releases in the last 12 months. This indicates a long-standing lack of release maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's prolonged inactivity. The non-archived status does not compensate for the absence of recent work.
The repository uses Composer, but no security scanning tooling was detected. This is a transparency and maintenance gap, though it is secondary to the package's abandonment status.
The repository is not archived, which preserves a potential maintenance path, but its last push was in January 2023 and the commit activity is currently absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.11|^3.0 | — | — |
symfony/process Version * | — | — |
nikic/php-parser Version ^4.2.2 | — | — |
symfony/validator Version * | — | — |
symfony/var-dumper Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.