The MIT license, clear documentation, tests, and organization-backed repository make the package transparent and straightforward to evaluate. However, it has had no release or commit activity for nearly nine years, and no security policy is published; use only if its stable, legacy behavior fits your needs.
45%
Total Score
50
70
50
The package has made no releases in nearly nine years, after 15 releases over its earlier lifetime. This is strong evidence of abandonment risk for a dependency, despite its previously regular release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push nearly nine years ago. There is no observed maintenance activity to offset the age of the latest release.
The repository has only 2 stars and no forks, indicating limited visible adoption. Popularity is supporting evidence rather than a verdict, but it offers little additional confidence for an inactive package.
The repository has no published security policy and no security scanning tools. This is a transparency and maintenance gap, especially for a dependency that has otherwise been inactive for years.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.0 | — | — |
webiny/std-lib Version ~1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.