Regular releases, a substantial README, tests, and a clear MIT license support adoption. However, no commits were recorded in the last three months, and the pre-1.0 version indicates limited maturity; use the replacement package instead.
38%
Total Score
75
100
79
75
Packagist marks the entire package as abandoned and names sigmaphp/sigmaphp-router as its replacement, which is a direct dependency risk despite other healthy evidence.
The repository recorded zero commits and zero active maintainers in the last three months, weakening the evidence that reported release activity will continue.
The repository has no security policy, reducing vulnerability-reporting transparency, although this is a secondary concern compared with the package abandonment status.
Version 0.1.16 is not a prerelease, but remaining before 1.0 signals a less mature compatibility baseline for a library dependency.
The sole workflow was fully audited with no dangerous triggers or audit findings, but both action references are unpinned, leaving a modest workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.