The package has a matching repository, a usable README, and no install-time scripts, keeping adoption straightforward. Its seven runtime dependencies and lack of tests or security policy provide limited supporting assurance.
42%
Total Score
0
50
67
75
The latest release was in October 2022, nearly four years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite a previously regular release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The repository is not archived, but that does not offset the lack of recent activity.
The package declares seven runtime dependencies, including framework, HTTP, routing, and database-related libraries. This increases maintenance exposure, but the profile is coherent rather than unusually excessive.
No license is declared, and neither the package nor the collected repository contains a license file. This leaves users without clear permission to rely on or redistribute the code.
A README is present and explains the package, but it is very short and explicitly describes the library as still in development. The absence of packaged tests and changelog is normal, while the repository also provides no test or changelog evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
j4mie/paris Version ^1.5.0 | — | — |
ramsey/uuid Version ^4.2 | — | — |
j4mie/idiorm Version ^1.5.0 | — | — |
symfony/routing Version ^5.4 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.