The package includes a clear MIT license, tests, release notes, and a matching repository reference. Its small user base, absent recent commits, and lack of security policy or scanning leave meaningful maintenance and transparency concerns.
62%
Total Score
63
50
83
67
The repository recorded zero commits and zero active maintainers in the last three months. Combined with no releases in over two years, this is the strongest abandonment concern in the assessment.
The package declares 10 runtime dependencies, including framework, database, mail, OAuth, and extension requirements. This is a substantial dependency surface that increases maintenance exposure, though it is consistent with a REST framework.
The package has existed since April 2015 with 10 releases, but it has had no release in the last 12 months; its latest registry release was January 7, 2024. That long publishing gap lowers confidence in ongoing maintenance.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This may reflect stability, but alongside absent commits it gives little evidence of active maintenance.
The repository has 7 stars and 2 forks, indicating a small adoption footprint. Popularity is supporting evidence only, but this provides little external maturity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kajna/purli Version dev-master | — | — |
pimple/pimple Version dev-main | — | — |
predis/predis Version v1.1.0 | — | — |
psr/container Version 1.1.0 | — | — |
psr/simple-cache Version ^1.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.