It has a clear README, tests, changelog, MIT licensing, and no install-time scripts. Open work remains untouched, the repository does not mention the package by name, and there is no security policy.
45%
Total Score
25
67
100
The latest release was about 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency whose compatibility may need maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, confirming that development is currently inactive rather than merely having a slow release cadence.
There were no new or closed issues or pull requests in the last month, while 7 issues and 10 pull requests remain open. This suggests unresolved maintenance demand.
The linked repository name does not match the package name and its README does not mention the package, making the package-to-source relationship less transparent despite the matching owner.
The repository is not archived, although its last push was about 8 years ago. The unarchived status is a positive administrative signal, but it does not compensate for the inactive release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silex/silex Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.