Tests, documentation, and licensing are solid. The package is not deprecated or archived, but its old release and absent recent commit activity make long-term maintenance uncertain.
58%
Total Score
83
100
75
83
The package has seven releases since 2016, but none in the last 12 months and its latest registry release is from November 2017. That long release gap raises abandonment risk.
The repository had no commits and no active maintainers in the last three months. Combined with the old release history, this is the strongest evidence of stalled maintenance.
Composer is used for the build, but no security-scanning tooling is present. The missing scanner is a hygiene gap rather than evidence that the package is unsafe to depend on.
The linked repository is not archived, and it was last pushed in July 2020. This is better than an archived project but still leaves several years without observed repository updates.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is not by itself evidence of abandonment or a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version ^2.7 | ^3.0 | — | — |
thecodingmachine/discovery Version ^1.2 | — | — |
symfony/dependency-injection Version ^2.3 | ^3.0 | — | — |
thecodingmachine/common-factories Version dev-master | — | — |
container-interop/service-provider Version ~0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.