The repository has only three files, no tests, and no security policy. It is not deprecated or archived, but the long silence and minimal project evidence make this a poor long-term dependency choice.
32%
Total Score
50
64
50
The last release was in May 2014, about 12 years ago, with no releases in the past 12 months. This is strong evidence of abandonment for a package intended as a maintained framework integration.
The complete artifact contains only README.md, composer.json, and one source file. That may be sufficient for a small provider, but it offers little evidence of testing or broader project maturity.
There are no open issues or pull requests and no issue or pull-request activity in the past month. Combined with the old release history, this supports an inactive-project assessment.
The repository name matches the package, but its README does not mention the package name. That weakens the evidence that the repository documentation fully supports this published package.
Composer is used for the build, but no security scanning tooling is present. This is a hygiene gap rather than evidence that the package is unsafe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silex/silex Version ~1.1 | — | — |
illuminate/database Version ~4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.