The declared MIT license and README make the package easier to inspect. Its seven runtime dependencies and repository/package name mismatch add uncertainty about ownership and upkeep.
38%
Total Score
50
79
75
The package has had no releases in the last 12 months, and its latest release was about 10 years ago. Six historical releases show it was published before, but do not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's long release gap and indicating little current maintenance capacity.
The linked repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether it is the package's actual source repository.
The repository has only 2 stars, 1 fork, and 2 watchers, providing little community evidence to compensate for the absence of recent maintenance.
The repository has no security policy, which reduces transparency for reporting vulnerabilities. This is a secondary concern for a small, inactive project rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/slim Version 2.4.0 | — | — |
twig/twig Version 1.* | — | — |
slim/views Version 0.* | — | — |
jms/serializer Version ^1.3 | — | — |
monolog/monolog Version ^1.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.