Its five runtime dependencies and Composer build setup are clear, and the repository still matches the package. However, the project offers no security policy or automated security scanning, leaving adoption dependent on very old source and release practices.
35%
Total Score
0
42
50
Neither the package metadata nor the checked files provide a license. Without clear permission to use, modify, and redistribute the code, dependency adoption carries a significant legal and transparency concern.
This package has only one release, published over 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push occurring in 2016. The long absence of development materially lowers maintenance confidence.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these figures provide no supporting evidence of an active user or contributor community.
Composer is used for the build, which is appropriate for this package, but no security-scanning tools are configured. The build setup is a small positive, while the missing scanning leaves a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.0 | — | — |
php-di/php-di Version ^5.3 | — | — |
nikic/fast-route Version ^1.0 | — | — |
kriswallsmith/assetic Version ^1.3 | — | — |
sunra/php-simple-html-dom-parser Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.