It has a clear MIT license, a usable README, and release notes for this version. Its small repository and lack of security tooling make long-term support harder to establish.
35%
Total Score
75
50
83
50
The package declares 10 runtime dependencies and no development dependencies, creating a relatively broad dependency surface for a small framework package. The signal does not show whether those dependencies are outdated or unsafe.
The package has had no release in more than 8 years, despite 9 releases overall. That long period without a new release is strong evidence of abandonment risk.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no release since February 2018. This materially increases abandonment risk.
The repository has 0 stars, 0 forks, and 1 watcher. Low popularity is only supporting evidence, but it provides little external evidence of maturity or ongoing use.
Composer is used for the build, but no security scanning tools are configured. That is a maintenance and transparency gap, although it is not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.0 | — | — |
silex/silex Version ~2.0 | — | — |
symfony/form Version ^3.2 | — | — |
symfony/config Version ^3.2 | — | — |
imagine/imagine Version ^0.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.