Usable in the short term, but maintenance appears effectively stopped (no releases and no recent repository activity since 2016). The repo also doesn’t appear to match the package name, which raises ownership/identity uncertainty.
38%
Total Score
50
70
The package’s last registry release was in 2016, about 9.8 years ago, with no releases in the last 12 months. That long gap is a strong indicator of abandonment risk for a dependency.
There were 0 commits in the last 3 months and 0 active maintainers in that window. With the long release gap, this supports a picture of stalled maintenance.
The linked repository does not match the package name and does not mention the package in the README. That mismatch can indicate the release may not truly belong to the repository you’re reviewing.
No GitHub Actions workflows were analyzed (0 workflows_total), so CI/security hygiene for this repository cannot be verified from this scan. This is a transparency gap rather than a positive signal of safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/css-selector Version ~2.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.