This is a long-established, currently usable package with 52 releases since 2015, a stable latest version, an active non-archived organizational repository, a license file, and no install-time lifecycle scripts. However, recent maintenance is thin: only one release in the last 12 months, one commit by one contributor, no repository tests or changelog, no security policy, and no security-scanning tooling. The organization backing and very recent repository push reduce abandonment concerns, but the limited recent activity and transparency gaps warrant caution before making it a critical dependency.
72%
Total Score
70
100
78
90
The package includes a substantial README and the repository uses GitHub Releases, which partly compensates for the absence of packaged tests and a changelog. Tests are absent from both the artifact and repository, leaving a genuine maintenance-quality gap.
The package has existed for 4,121 days and has 52 releases, but only one release occurred in the last 12 months. The recent release and very recent repository push are reassuring, while the low release cadence suggests slower maintenance.
All recent commits come from one contributor, creating a concentrated maintenance risk. The organization-owned repository provides some capacity to hand maintenance off, so this is caution rather than severe risk.
There was one commit in the last 3 months from one active maintainer, showing some current activity but a very low recent maintenance rate.
There are two open issues and no recent issue or pull-request activity. The lack of recent closures or merges provides little evidence of active issue management.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
symfony/cache Version ^5.4 || ^6.4 || ^7.2 | — | — |
symfony/security-core Version ^5.4 || ^6.4 || ^7.2 | — | — |
linkorb/userbase-role-contracts Version ^2.0 | — | — |
symfony/event-dispatcher-contracts Version ^2.0 || ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.