The repository includes tests, release notes, and a clear MIT license. Install-time scripts and the lack of security scanning add some maintenance friction, while the project has seen no commits or releases since March 2018.
40%
Total Score
50
79
50
The package is over 8 years old, has had 7 releases, and has had no release in the last 12 months; the short historical release burst does not offset the prolonged inactivity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring in March 2018 and indicating strong abandonment risk.
The package runs post-install and post-update scripts, which create additional installation behavior that consumers must account for even though no maliciousness judgment is made here.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this matters more given the project's long inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.0 | — | — |
roave/security-advisories Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.