The source is still being updated, with tests, a clear license, and no install-time scripts. Its one-person maintenance base and repository mismatch add adoption risk; use tjm/sy-web instead.
38%
Total Score
67
71
75
Packagist marks the entire package as abandoned and names tjm/sy-web as its replacement. This is a direct adoption risk even though the release itself is not individually withdrawn.
The repository is owned by an individual account rather than an organization, so the concentrated maintenance activity has no demonstrated organizational handoff support.
One contributor made all 14 commits in the last 3 months, leaving no demonstrated backup maintainer. This increases continuity risk for a package already marked abandoned.
The repository name does not match the package name and its README does not mention the package. The linkage is therefore less transparent and may indicate the package is hosted alongside unrelated project code.
No repository security policy was found. This is a transparency and response-process gap, but it is secondary to the package's abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version >=3.0 <7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.