Its six runtime dependencies increase the cost of taking over or replacing the package. The source repository could not be found, so maintenance and provenance cannot be verified.
15%
Total Score
50
33
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk even though the deprecation is not limited to this release.
The package has only two releases and none in the last 12 months; its latest release was about 10 years ago. That strongly indicates abandonment rather than active maintenance.
Six runtime dependencies make continued use more dependent on an old surrounding stack and increase replacement or maintenance effort. The signal does not show dependency vulnerabilities by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.18 | — | — |
silex/silex Version ~2.0 | — | — |
sanpi/twitter-bootstrap-installer Version ~1.1 | — | — |
pomm-project/pomm-service-provider Version dev-master | — | — |
incenteev/composer-parameter-handler Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.