Risky to adopt: the package appears effectively dormant, with no release or commit activity for nearly two years. It is correctly linked, licensed, and documented, but its unfinished status, lack of tests, and missing security process add maintenance risk.
40%
Total Score
50
50
71
83
There were zero commits and zero active maintainers in the last three months, consistent with the nearly two-year release gap. This is strong evidence of abandonment risk.
Nineteen runtime dependencies create a broad maintenance and compatibility surface for a small, early-stage authentication package. The dependency list is visible, but the package's long-term inactivity makes keeping that surface current less credible.
The package includes a readable README and release notes for version 0.2.0, which improves transparency. The README describes the project as still in development; the absence of published tests is normal for an artifact, but the repository also reports no tests.
The package has only three releases and none in the last 12 months; its latest release was nearly two years ago. This is a meaningful maintenance concern for an authentication package.
Composer build tooling is present, but the repository has no security scanning tools. For authentication software, that is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/csrf Version ^1.5 | — | — |
slim/psr7 Version ^1.7 | — | — |
slim/slim Version ^4.14 | — | — |
slim/flash Version ^0.4.0 | — | — |
slim/twig-view Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.