The package includes a README, tests, and a clear MIT declaration. Its last release was over six years ago, and the repository could not be found, leaving maintenance and provenance unverified. The assessed version also differs from the recorded latest version.
38%
Total Score
50
50
70
100
The package has had no releases in over six years and none in the last 12 months, despite only four releases overall. This is strong evidence of abandonment for a framework intended as a project foundation.
Nine runtime dependencies support substantial framework functionality, but the breadth of the dependency surface adds maintenance exposure for an otherwise long-unmaintained package.
Two registry accounts have publish access, but this is administrative metadata and does not compensate for the absence of recent release activity.
The release is marked as a stable major version rather than a prerelease, which is positive, but the recorded latest version is v1.0.2 while the assessed release is v1.0.4, reducing confidence in the release metadata.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/slim Version 3.12.3 | — | — |
slim/twig-view Version 2.5.1 | — | — |
monolog/monolog Version 2.1.1 | — | — |
robmorgan/phinx Version 0.12.3 | — | — |
odan/twig-assets Version 3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.