The MIT license, comprehensive tests, changelog, and matching repository make the package transparent and straightforward to inspect. Use the registry-listed replacement instead, because this release is no longer maintained.
18%
Total Score
0
67
50
Packagist marks the entire package as abandoned and provides a replacement repository, which is a severe adoption and maintenance risk.
The latest release was in June 2022, with no releases in the last four years despite 17 releases overall; the previously active cadence has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and indicating no current maintenance.
The repository has no security policy, reducing the transparency of vulnerability reporting, although this is secondary to the package's explicit abandonment.
Both workflows were analyzed without dangerous triggers, sinks, or audit findings, but all 10 referenced actions are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^6.0 | — | — |
doctrine/orm Version 2.12.* | — | — |
doctrine/dbal Version 3.3.* | — | — |
tuzex/timekeeper Version 0.1.* | — | — |
webmozart/assert Version 1.10.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.