Risky to adopt: the package has had no release for over 11 years and its repository has seen no commits for over 10 years. It has solid basic packaging and licensing, but the long abandonment gap outweighs those strengths.
43%
Total Score
0
100
67
75
The latest release was published in June 2015, with no releases in the last 12 months. That long period without updates is strong evidence of abandonment for a framework dependency.
There were zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this indicates no current maintenance capacity.
Composer is used for builds, but no security scanning tooling is present. This is a modest transparency gap, though it is secondary to the much older maintenance history.
The repository is not marked archived, which avoids the strongest abandonment signal, but it was last pushed in June 2016 and therefore has still been inactive for over 10 years.
The repository has no published security policy. For a framework intended to handle web requests, that weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.