The project offers little consumer documentation and has no visible security policy or scanning. Its dependency set is sizeable for a small framework, so maintenance gaps could be harder to assess.
42%
Total Score
50
50
67
75
The package is about 2470 days old, has only 5 releases, and has had no releases in the last 12 months; the latest release was in February 2020. This indicates prolonged abandonment risk.
The framework declares 11 runtime dependencies, including several substantial components, while the project has very little visible maintenance evidence. This increases the surface that consumers must trust and keep compatible.
The package includes a README, but it is only 290 characters and says documentation is still forthcoming. Missing tests and changelog files are normal packaging practice and are not counted against it.
The repository is owned by an individual user rather than an organization, and the registry namespace does not add evidence of organizational backing. This provides little maintenance capacity beyond the single project owner.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these values provide no external indication of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.5 | — | — |
symfony/yaml Version ^5.0 | — | — |
bramus/router Version ^1.4 | — | — |
monolog/monolog Version ^2.0 | — | — |
symfony/console Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.