The repository is small, has no security policy, and its license declaration conflicts with the Apache-2.0 file. It has a README and no install-time scripts, but those positives do not offset the maintenance concerns.
18%
Total Score
0
58
75
Packagist marks the entire package as abandoned and recommends pneuma/framework, making this release unsuitable as a new dependency despite no release-specific withdrawal.
The latest release was in July 2020, with no releases in the last six years; the package has effectively stopped receiving published maintenance.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and elevated abandonment risk.
The artifact includes an Apache-2.0 license file, but the manifest declares a proprietary license; this mismatch creates avoidable uncertainty for downstream users.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap for a framework dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.0 | — | — |
slim/slim Version ^4.4 | — | — |
twig/twig Version ^3.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.