The MIT license, tests, and package-matching repository make it easier to inspect and adopt. Support is thin: one maintainer, no security policy, and nearly seven years without maintenance activity.
42%
Total Score
25
75
50
Only two releases exist, with the latest published in November 2019 and none in nearly seven years. This is strong evidence of abandonment for a framework dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and leaving current maintenance unconfirmed.
One registry maintainer can be sufficient for a small project, but it creates a thin support base when combined with the absence of recent release and commit activity.
No security policy was found, reducing transparency about vulnerability reporting and response. This is a meaningful hygiene gap for a framework package, though not severe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.1 | — | — |
relay/relay Version ~2.0 | — | — |
luoluolzb/di Version ^1.0 | — | — |
psr/container Version ^1.0 | — | — |
nikic/fast-route Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.