40%
Total Score
unhealthy
Risky: a single release from 2015 and no recent repository activity make abandonment the central concern.
This package has only one release, published about 11 years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance or compatibility work.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has been inactive since its initial release.
The artifact and repository contain tests, and this version has a GitHub release, providing useful validation evidence. The missing README and changelog are minor concerns here because tests and release packaging are present, while the absence of a README still reduces consumer guidance.
Composer is used for build and dependency management, but no security scanning tools are configured. The tooling is adequate for basic packaging, with limited evidence of security maintenance.
The linked repository has no security policy. For an inactive package, this further limits transparency about vulnerability reporting and support expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silex/silex Version v1.2.3 | — | — |
simple-bus/message-bus Version v1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.