It includes a README, tests, a declared MIT license, and a matching source repository. Its large runtime dependency set, install hooks, and lack of security tooling increase upkeep concerns.
38%
Total Score
50
50
78
75
The package has had only two releases, with the latest published about 8 years ago and none in the last 12 months. This is strong evidence of abandonment, though the stable version history avoids prerelease uncertainty.
There have been zero commits and zero active maintainers in the last 3 months, while the last repository push was about 8 years ago. This strongly indicates that maintenance has stopped.
The package declares 21 runtime dependencies, including multiple Symfony packs and framework components. That breadth increases compatibility and upkeep burden for an old application.
Composer post-install and post-update scripts run during dependency operations. Such hooks can be legitimate, but they add execution and maintenance surface when their behavior is not otherwise evidenced.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a dormant project, although the lack of open work is not itself proof of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lts Version ^4@dev | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/form Version ^4.0 | — | — |
symfony/yaml Version ^4.0 | — | — |
symfony/asset Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.