The MIT license and matching license file make reuse clear, while the README and release notes improve transparency. Install-time scripts and 17 runtime dependencies add maintenance surface, and no security policy is present.
42%
Total Score
50
88
50
The package declares 17 runtime dependencies and no development dependencies, creating a relatively broad runtime maintenance surface for a small example application.
post-create-project-cmd and post-update-cmd execute during Composer operations, increasing installation and update complexity and the amount of package behavior consumers must trust.
This package has only one release, published about 9 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
Composer build tooling is present, but no security scanning tools are configured. For a package this old, that leaves an unaddressed maintenance and security-hygiene gap.
The repository has no security policy. This reduces transparency about how vulnerabilities are reported and handled, especially for a package with authentication-related setup.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/slim Version ^3.0 | — | — |
twig/twig Version ^1.0 | — | — |
lagan/core Version ^1.0 | — | — |
slim/flash Version ^0.2 | — | — |
slim/twig-view Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.