Risky to adopt: this package has clear documentation, tests, licensing, and organizational backing, but its last release and repository activity were nearly eight years ago. The long maintenance gap makes future compatibility and support uncertain.
43%
Total Score
50
50
67
75
The package has 23 releases and a historically rapid median release interval, but it has had no release in nearly eight years and none in the last 12 months. That prolonged release gap is a significant abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old last release, this is the strongest evidence that maintenance has stopped.
This is a Dockerized application skeleton with 15 runtime dependencies, including storage, messaging, HTTP, and framework components. That breadth increases compatibility and maintenance exposure, especially given the long release gap.
The repository has 33 stars and 3 forks, indicating some real adoption, but these modest counters are only supporting evidence and do not outweigh the extended maintenance gap.
The repository uses Composer, confirming basic build tooling, but it has no security-scanning tools. This is a transparency and maintenance gap, though not as severe as the lack of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
monolog/monolog Version ^1.21 | — | — |
nikic/fast-route Version ^1.0 | — | — |
prooph/pdo-event-store Version ^1.0 | — | — |
roave/security-advisories Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.