The README, matching repository, and MIT declaration provide basic transparency and a clear installation path. Long-term inactivity, a single maintainer, and no security policy make future fixes and oversight uncertain; pinning this release is safer than expecting active support.
43%
Total Score
33
71
75
The package has had no release in nearly nine years, with zero releases in the last 12 months; this is strong evidence of abandonment risk despite the nine-release history.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for years and unlikely to receive fixes.
One registry maintainer is consistent with a user-owned project, but the single-person publishing base leaves limited visible maintenance capacity when combined with the inactive repository.
There were no new or closed issues or pull requests in the last month; with no recent commits, this provides no evidence of active support.
Composer is used for the build, but no security scanning tools are present; this is a modest transparency and oversight gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/slim Version ^3.8 | — | — |
symfony/yaml Version ^3.3 | — | — |
simplon/mysql Version ^2.2 | — | — |
symfony/console Version ^3.3 | — | — |
vlucas/phpdotenv Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.