Its small dependency surface and clear README reduce integration uncertainty. The organization-owned repository is licensed and not archived, but there is no recent maintenance or security-policy evidence.
38%
Total Score
50
60
75
The package has had only two releases, with none in the last 12 months; its latest release dates from June 2019, indicating prolonged release inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and strong abandonment risk.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but it provides little evidence of an active user or contributor base.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is less significant than the absence of recent maintenance.
Version v0.9.0 is not a stable major release, which adds API-change uncertainty; the package is not marked as a prerelease, partially offsetting that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
litphp/bolt Version ^0.9 | — | — |
zendframework/zend-diactoros Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.