The project has tests, release notes for this version, an MIT license, and organization backing. The missing README and security policy reduce transparency, while install-time scripts add some maintenance and supply-chain exposure.
55%
Total Score
75
79
50
Composer post-install and post-update scripts add execution during dependency operations, creating extra maintenance and supply-chain exposure compared with a package without install hooks.
Tests and a GitHub release with notes for this version are positive, but the package has no README, leaving library consumers with less integration guidance.
The package has 35 releases over about 5 years, but none in the last 12 months; the long pause lowers confidence that maintenance is continuing.
The repository recorded no commits and no active maintainers in the last 3 months, which supports concern about slowed maintenance.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
slim/http Version ^1.1 | — | — |
slim/psr7 Version ^1.0 | — | — |
slim/slim Version ^4.2 | — | — |
twig/twig Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.