The README is brief, and the repository has no security policy or security scanning, limiting transparency. Prefer the listed replacement package for new projects.
18%
Total Score
0
50
50
83
Packagist marks the package abandoned at package scope and names doy leaf-php/dphp as its replacement, making this release unsuitable for a new dependency.
The package has only two releases, with the latest published in May 2018 and none in the last 12 months; this indicates long-term abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with an unmaintained project.
The package declares seven runtime dependencies and no development dependencies, which is a relatively broad runtime surface for a small framework and provides little evidence of maintained development practices.
The artifact includes a license file and the repository also has one, but the manifest declares MPL-2.0 while the detected license is GPL-3.0; this mismatch needs clarification before adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.1 | — | — |
catfan/medoo Version ^1.5 | — | — |
doctrine/orm Version ^2.5 | — | — |
doylee/wafphp Version dev-master | — | — |
nikic/fast-route Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.