Stable versioning, clear licensing, and repository tests provide useful baseline transparency. The package is deprecated, archived, and has had no recent commits, so pinning it creates substantial abandonment risk.
12%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption and maintenance warning for the assessed release.
The package has had five releases since July 2020, but none in the last 12 months; its latest release was December 22, 2021. This strongly indicates prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months. This reinforces the abandonment risk shown by the archived status.
The linked repository is archived, and it was last pushed on April 22, 2022. An archived source project is not an active maintenance base.
The repository name does not match the package name and its README does not mention the package. Although naming differences can occur in project layouts, this leaves package-to-source ownership less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4 | — | — |
symfony/yaml Version ^5.4 | — | — |
symfony/string Version ^5.4 | — | — |
composer/semver Version 1.* | — | — |
symfony/console Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.