php microframework
40%
Total Score
unhealthy
Risky: no releases or commits since 2020 leave this release effectively unmaintained.
The package has had no release in over 6 years: its latest release was in April 2020, with no releases in the last 12 months. This strongly raises abandonment risk despite six historical releases.
There were no commits and no active maintainers in the last 3 months, consistent with the last push being in 2020. This is the strongest maintenance concern for depending on the release.
The package declares 13 runtime dependencies, creating a comparatively broad dependency surface for a small framework. The signal provides no evidence that these dependencies are unsafe, so this is a modest maintenance concern rather than a severe risk.
No license is declared, and neither the package nor the linked repository contains a license file. That leaves the legal terms for using this dependency unclear.
Only one registry account can publish the package. Because the linked project is owned by an individual rather than an organization, there is little visible publishing redundancy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 3.* | — | — |
filp/whoops Version ^2.5 | — | — |
nyholm/psr7 Version ^1.2 | — | — |
pyrocms/lex Version 2.2.* | — | — |
monolog/monolog Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.