The MIT license, tests, documentation, and release notes improve transparency. Organization backing and a matching repository support provenance, but no security scanning or policy leaves maintenance practices unclear.
36%
Total Score
50
67
75
This is the package's only release, published about 11 years ago, with no releases in the last 12 months. That long period without version activity is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release silence. No provided signal shows compensating maintenance activity.
Six issues remain open, while there were no new or closed issues and no pull-request activity in the last month. This suggests unresolved maintenance needs despite the small issue count.
Composer is used as a build tool, but no security-scanning tools are configured. That is a transparency and maintenance-process gap, though it is not evidence of malicious behavior.
The repository has no published security policy. Consumers therefore have no documented security-reporting path or stated response process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version 1.4.* | — | — |
symfony/finder Version ~2.6 | — | — |
symfony/filesystem Version ~2.6 | — | — |
php-riak/riak-client Version 1.0.*@dev | — | — |
symfony/security-core Version ~2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.