35%
Total Score
0
100
71
50
Only two releases were published, with the latest on February 1, 2022; there have been no releases in roughly 4 years and 7 months. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package having been inactive since its last release. No provided signal shows compensating maintenance activity.
The artifact has no README, which makes integration harder for a library consumers must understand. The absence of tests and a changelog is normal packaging practice and does not add risk by itself.
Composer is used for the build, but no security-scanning tools are present. This is a modest transparency and maintenance gap, though it does not outweigh the direct inactivity evidence.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a hygiene gap rather than evidence that the release is unsafe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/route Version ^5.1 | — | — |
php-di/php-di Version ^6.3 | — | — |
laminas/laminas-diactoros Version ^2.8 | — | — |
laminas/laminas-httphandlerrunner Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.