Recent repository activity has stopped, and the project lacks a security policy while its three workflow actions are unpinned. Long history, tests, release notes, licensing, and organization backing provide useful counterweight.
44%
Total Score
75
75
75
The package is flagged as borrowing symfony/string's identity, with an explicit lookalike match and no indication that it is a transparent fork. Consumers may have intended symfony/string instead, making this a severe supply-chain transparency risk.
The package has existed for over 14 years with 51 releases, but only 1 release in the last 12 months. Its long history supports maturity while the recent cadence suggests slower maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent release shows the project is not abandoned outright, but current maintenance activity is absent.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. The absent scanning is a modest hygiene weakness, not a standalone severe risk.
No security policy was found in the repository. That weakens vulnerability-reporting transparency for a package used in routing infrastructure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/routing Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.