It has a README, MIT declaration, and a matching source repository, but only two stars and no security scanning reduce confidence in ongoing support. Pinning this release leaves you responsible for maintenance gaps.
43%
Total Score
38
50
72
75
The package has had no release in about four years, despite 18 releases overall; this is strong evidence that maintenance has stopped.
There were no commits and no active maintainers in the last three months, reinforcing the release-history evidence that development has been dormant for about four years.
The package declares 18 runtime dependencies, creating a broad dependency surface for a framework bundle, though the signal does not show that these dependencies are unmaintained or unsafe.
Two registry publishing accounts are present. This is a small maintainer base, but the linked repository is user-owned, so the registry count is not by itself decisive.
The repository is owned by an individual rather than an organization, so there is no observed organizational backing to compensate for the thin activity and adoption signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.3.0 | — | — |
slim/slim Version ^4.6.0 | — | — |
cocur/slugify Version ^4.0 | — | — |
predis/predis Version ^2.0@dev | — | — |
monolog/monolog Version ^1.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.