Documentation and packaging are solid, with tests, release notes, and a clear license. The project is archived, has had no release in nearly 10 years, and shows no recent commits, so pinning this dependency carries substantial abandonment risk.
12%
Total Score
0
50
83
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk for a dependency, even though the assessed release is identified separately.
The package has only 5 releases, with the latest published about 10 years ago and none in the last 12 months. This strongly indicates abandonment for a package intended as a framework integration.
The repository had no commits and no active maintainers in the last 3 months. This confirms the lack of current maintenance rather than merely showing a slow release cadence.
The linked repository is archived, and its last push was about 6 years ago. Archived source indicates the project is no longer actively maintained.
The repository uses Composer for builds, which fits the package ecosystem. No security scanning is configured, a minor hygiene gap, but it does not outweigh the project’s archived status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silex/silex Version ~2.0 | — | — |
jms/serializer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.