Package Health

aalfiann/slim-skeleton

The MIT license, clear repository match, and Composer-based structure make the package transparent to inspect. One maintainer, no security policy or scanning, and no development activity since March 2020 make it a risky foundation for a new application.

Latest 1.6.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had no release in more than six years, despite 14 releases since 2018. That long gap is strong evidence of abandonment risk for a project template.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history and leaving current maintenance capacity unproven.

Maintainerscaution

Only one registry publishing account is listed, and the project is user-owned rather than organization-backed. This creates a thin maintenance base, although it does not by itself indicate abandonment.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are present. The missing automated security checks modestly increase maintenance risk for a security-focused application template.

Security policycaution

The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a meaningful hygiene gap for a web application skeleton.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

M ABD AZIZ ALFIAN

Direct Dependencies

DependencyLast ReleaseScore
slim/csrf
Version ^0.8.3
—
—
slim/slim
Version ^3.1
—
—
twig/twig
Version ~2.0
—
—
slim/flash
Version ^0.4.0
—
—
slim/twig-view
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform