Risky to adopt because this is a one-release project with no commits in about three months and no release for about 13 months. It has a usable README, a stable MIT-licensed release, and no deprecation or archive status, but maintenance and security coverage are thin.
48%
Total Score
0
50
81
50
The package has only one release, published about 13 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance for a framework dependency.
The repository recorded no commits and no active maintainers in the last three months. With only one release, this reinforces the risk that development has stalled.
The framework declares 14 runtime dependencies and no development dependencies. That is a relatively broad runtime surface for a small, single-release project and increases the maintenance burden.
Composer build tooling is present, but no security scanning tools are configured. For a web framework, that leaves an important part of maintenance hygiene uncovered.
The repository has no security policy. This is a transparency gap for a framework handling web requests, sessions, validation, and related application concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.15 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
league/route Version ^5.0 | — | — |
symfony/yaml Version ^6.0 | — | — |
league/plates Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.