The release is stable and documented, with an Apache-2.0 license and release notes for this version. Its source repository is archived, with no commits in the last three months, and the package is marked abandoned without a replacement.
12%
Total Score
0
57
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe maintenance warning for a dependency rather than a release-specific withdrawal.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with its archived status, this indicates no current capacity to address defects or compatibility changes.
The linked repository is archived and was last pushed about four years ago, indicating that active maintenance has ended. This outweighs the otherwise useful package documentation and stable versioning.
The package has only four releases since 2015, and none in the last year; the latest release was in March 2022. The long release intervals are consistent with an abandoned project, despite a release note for this version.
Composer is used for the build, but no security scanning tooling is present. That is a secondary transparency gap and does not offset the repository's abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.