The package includes tests, a changelog, a clear license, and organization-backed ownership. Its release and commit activity stopped in June 2018, while security scanning and a security policy are absent.
43%
Total Score
63
100
72
83
The package has 64 releases, but its latest release was over eight years ago and it had no releases in the last 12 months. The earlier regular cadence shows past maturity but does not offset the prolonged inactivity.
There were no commits and no active maintainers in the last three months, consistent with the repository's last push being over eight years ago. This is strong evidence of abandonment risk.
There were no new or closed issues or pull requests in the last month, and nine issues remain open. Combined with zero recent commits, this suggests unresolved maintenance rather than an actively managed project.
The repository has 45 stars and 14 forks, showing some historical use but limited reach. Popularity is supporting evidence and cannot counter the absence of recent maintenance.
Composer and Phing are used for builds, showing established project tooling. No security scanning tools are configured, leaving a meaningful security-maintenance gap for a web server.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
rhumsaa/uuid Version ~2.8 | — | — |
appserver-io/http Version ~2.0 | — | — |
appserver-io/logger Version ~2.0 | — | — |
appserver-io/server Version ~10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.