The framework includes tests, a README, release notes, and an MIT license. Its small audience, absent recent commits, missing security policy, and unpinned workflow actions add maintenance and build-integrity concerns.
20%
Total Score
75
100
69
50
Packagist marks the entire package as abandoned and names sigmaphp/sigmaphp as its replacement. This directly signals that new dependencies should not be placed on this package.
The package has 5 releases over 460 days, including 3 in the last 12 months with a median interval of about 56 days. This shows some release activity, but it does not offset the package-level abandonment status.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository is not archived and a recent push is reported, the observed development activity is currently absent.
The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of external adoption or community support. Popularity is supporting evidence only, but this offers no compensating signal for the maintenance gap.
The linked repository has no security policy. For a web framework, this reduces transparency about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
agashe/sigmaphp-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.