The small codebase includes tests, a README, an MIT license, and no install-time scripts. Its single maintainer, absent security policy, and lack of recent repository activity leave limited evidence of ongoing support.
40%
Total Score
33
100
72
83
The package has had no releases in the last 12 months, and its three releases were concentrated in February 2019. This is strong evidence of abandonment risk for a dependency released over seven years ago.
There have been zero commits and zero active maintainers in the last three months, consistent with the release history and indicating materially elevated abandonment risk.
Only one registry account has publish access. This is a thin publishing base and increases continuity risk when combined with the absence of recent activity.
The repository is owned by an individual account rather than an organization, so the single-maintainer signal is not compensated by visible organizational backing.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little external evidence of active use or support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.4 || ^4.1 | — | — |
jms/serializer Version ^1.12 | — | — |
symfony/validator Version ^3.4 || ^4.1 | — | — |
symfony/twig-bundle Version ^3.4 || ^4.1 | — | — |
jms/serializer-bundle Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.