The repository still includes tests, a usable README, and an MIT license. Workflow image pinning and missing security scanning add maintenance risk.
43%
Total Score
50
79
50
The package has had no releases in the last 12 months, and its latest release was in April 2023, roughly 3 years and 4 months ago. That strongly suggests the package is no longer actively maintained.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. This is a substantial abandonment concern.
The repository has 1 star, 0 forks, and 1 watcher. Low adoption is only supporting evidence, but it offers little external validation or contributor depth.
Composer is used for the build, but no security-scanning tools were detected. That is a modest transparency and maintenance weakness, not evidence that the package is unsafe by itself.
The repository has no security policy. For a framework foundation package, this makes vulnerability reporting and maintenance expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.6 | — | — |
slim/slim Version ^4.11 | — | — |
twig/twig Version ^3.4.3 | — | — |
doctrine/dbal Version ^3.5.2 | — | — |
monolog/monolog Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.