MIT licensing and a repository that matches the package make its provenance clear. The source has no tests or security policy, limiting confidence in future fixes and review.
42%
Total Score
0
72
75
The package has had no release in over 9 years, and its latest release was in March 2017. This is strong evidence of abandonment risk despite a history of seven releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no observed maintenance.
The package includes a README and has a GitHub release for this version, but the repository reports no tests and the README is only 39 characters. The missing tests reduce confidence in a small, old codebase.
The repository has zero stars and forks and one watcher. Low adoption is supporting evidence of limited community validation, but it is not decisive by itself.
Composer is used for the build, providing basic project tooling, but no security-scanning tools are configured. This is a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dez-php/dez-di Version >=1.0 | — | — |
dez-php/dez-http Version >=1.0 | — | — |
dez-php/dez-event Version >=1.0 | — | — |
dez-php/dez-router Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.