It has tests, a clear MIT declaration, and an organization-owned repository. Its broad dependency set and missing security policy add maintenance overhead, so pinning this release is preferable.
56%
Total Score
50
50
75
50
Only three releases have appeared since December 2015, with none in the last four years; the long release interval materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent releases and indicating inactive maintenance.
The release declares 29 runtime dependencies, creating substantial update and compatibility surface for a framework; no provided signal shows that this dependency burden is actively managed.
Composer post-install and post-update scripts run during dependency operations, increasing operational complexity and the code executed during installation, though this is not severe on its own.
There are 28 open issues but no new or closed issues and no pull-request activity in the last month, suggesting unresolved maintenance demand.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.3 | — | — |
phpsgi/funk Version 1.0.x-dev | — | — |
c9s/webaction Version 4.0.x-dev | — | — |
corneltek/pux Version 2.0.x-dev | — | — |
phifty/locale Version ^3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.