The project includes tests, a clear README, and an MIT license. Its single-contributor history and prerelease status call for caution before adopting it.
58%
Total Score
50
50
86
75
The package declares 17 runtime dependencies for a small web framework, increasing the maintenance surface and the number of upstream components consumers must track.
The package is 167 days old with three releases, all published within hours, so its longer-term maintenance pattern is not yet established.
One contributor made 100% of the recent commits, leaving no demonstrated contributor redundancy for maintenance or review.
Only one commit was recorded in the last three months, showing limited recent development activity even though the repository is not abandoned.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
filp/whoops Version ^2.15 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
league/event Version ^3.0 | — | — |
league/route Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.