58%
Total Score
caution
Usable with caveats: release activity stopped over two years ago, despite solid package structure and tests.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. That is consistent ownership, though it indicates a thin backing structure.
The package has seven releases, but none in the last 12 months and the latest registry release was over two years ago. Earlier releases were reasonably spaced, which partly offsets but does not remove the current maintenance concern.
There were no commits and no active maintainers in the last three months, while the last recorded push was over two years ago. This is a meaningful abandonment risk.
The repository has zero stars and forks and only one watcher, providing little evidence of a broad user or contributor community. Low popularity is supporting evidence rather than a verdict by itself.
Composer build tooling is present, but no security scanning tools were detected. That leaves a gap in automated security oversight for a framework package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
geekmusclay/orm Version ^0.4.0 | — | — |
guzzlehttp/psr7 Version ^2.4 | — | — |
geekmusclay/router Version ^0.6.0 | — | — |
geekmusclay/di-container Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.