The package includes a clear README, matching Apache-2.0 licensing, and a moderate dependency set. There is no repository security policy or security scanning, adding transparency risk.
40%
Total Score
0
50
79
75
The package has 76 releases since 2019, but none in the last 12 months; its latest release was over three years ago, indicating prolonged release inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the evidence of stalled maintenance.
Six runtime dependencies form a meaningful but not unusually large dependency surface for a PHP framework; this adds some maintenance exposure without being excessive.
Composer is used as a build tool, but no security scanning tools are configured, leaving automated security coverage unverified.
The repository has no security policy, so users have no documented security-reporting path or stated response process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.0 | — | — |
psr/container Version * | — | — |
yosymfony/toml Version * | — | — |
monolog/monolog Version ^1.24 | — | — |
mashape/unirest-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.