Risky to adopt: the last release was nearly eight years ago and the repository has had no commits or active maintainers in the past three months. The package is licensed, tested, and not deprecated, but its prolonged inactivity makes abandonment a serious concern.
42%
Total Score
0
79
83
The package has had only 3 releases, with the latest nearly eight years ago and none in the last 12 months. This is strong evidence of stagnation for a framework dependency.
The repository recorded 0 commits and 0 active maintainers in the past three months, with the last push in November 2018. That sustained inactivity is a serious abandonment risk.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency gap, secondary to the much more significant inactivity concern.
The repository has no security policy. For a web framework this reduces vulnerability-reporting transparency, though it is less consequential than the prolonged lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4 | — | — |
butterycrumpet/supersimpledi Version ^0.9.0 | — | — |
butterycrumpet/supersimple-kernel Version ^0.0.2 | — | — |
butterycrumpet/supersimple-logger Version ^0.1.0 | — | — |
butterycrumpet/supersimple-routing Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.