The package is clearly licensed and includes tests, but those positives do not offset its lifecycle state. Choose an actively maintained Symfony integration instead.
12%
Total Score
25
100
40
50
Packagist marks the entire package as abandoned, with no replacement supplied. Package-level deprecation is a severe adoption risk even though this release is stable.
The package has 20 releases, but its latest release was in November 2017 and it had no releases in the last 12 months. The historical cadence does not compensate for the prolonged lapse.
There were zero commits and zero active maintainers in the last 3 months, consistent with the archived repository and indicating no current maintenance capacity.
The linked repository is archived and was last pushed in November 2017, indicating the source is no longer maintained.
The repository is owned by an organization, which provides some ownership context. It does not compensate for the package being abandoned and the repository being archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version * | — | — |
webforge/utils Version * | — | — |
webmozart/json Version * | — | — |
vlucas/phpdotenv Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.