The repository is tiny and has no security scanning, although it retains a README, changelog, build configuration, and clear package ownership. It is licensed, not archived, and correctly linked, but the maintenance evidence is too weak for an unattended dependency.
40%
Total Score
75
79
50
Only two releases exist, with none in the last 12 months; the latest was over 7 years ago. This is strong evidence of stalled maintenance for a dependency, despite the stable 2.0.0 version.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The repository has 0 stars, 1 fork, and 3 watchers, indicating very limited adoption or community visibility. Popularity is supporting evidence only, but it provides no meaningful compensating signal here.
Composer and Phing build tooling are present, but no security-scanning tool is configured. That is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
No repository security policy is present, reducing the documented path for reporting vulnerabilities. This matters more because there is also no recent activity or security-scanning evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
appserver-io-psr/application Version ~1.0 | — | — |
appserver-io-psr/application-server Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.