Unfit to use: the package is deprecated and its source repository is archived, with no commits in the last three months. It has a valid license and repository tests, but there is no evidence of ongoing maintenance for a security-focused dependency.
12%
Total Score
50
50
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the release.
The repository had zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance or security response capacity.
The linked repository is archived and was last pushed in April 2022, indicating that active development has ended. This outweighs the package's otherwise usable structure and license.
The package has had no releases in the last 12 months, and its latest release was in December 2021. The five-release history shows an established package, but not one receiving current updates.
The linked repository name does not match the package name and its README does not mention the package. Because the repository is otherwise linked under the same organization, this is a caution about package-to-source transparency rather than conclusive evidence of unrelated ownership.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4 | — | — |
phpids/phpids Version dev-master | — | — |
symfony/config Version ^5.4 | — | — |
symfony/mailer Version ^5.4 | — | — |
symfony/string Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.