The package includes a readable guide, tests, and release notes, and it has no install scripts or deprecation notice. Its small user-owned project and lack of security tooling leave limited assurance for a production dependency.
43%
Total Score
0
75
75
Only two releases were published, with none in the last four years; the latest release is from July 2022. This is strong evidence that maintenance has stopped.
There were zero commits and zero active maintainers in the last three months, consistent with the package having received no maintenance since 2022.
Composer is used for builds, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than proof of a security problem.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or explaining how they are handled.
Version 0.1.1 is not a stable major release, which adds maturity risk alongside the lack of recent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/http Version ^1.0 | — | — |
slim/psr7 Version ^1.0 | — | — |
slim/slim Version ^4.10 | — | — |
catfan/medoo Version ^2.1 | — | — |
lcobucci/jwt Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.