Clear licensing, documentation, tests, and a small dependency set support adoption. The missing security policy, absent security scanning, and very small repository audience leave limited evidence of ongoing stewardship.
42%
Total Score
75
100
78
75
The latest release was published in August 2020, and there have been no releases in the last six years despite five total releases. This is strong evidence that maintenance has stopped.
There are no open issues or pull requests and no issue or pull-request activity in the last month. Combined with the old latest release, this supports a conclusion of inactive maintenance.
The repository has one star, zero forks, and one watcher, giving little evidence of a broad user or contributor community to help sustain the project.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing quality oversight, although it is secondary to the long inactivity period.
The repository has no SECURITY.md or other detected security policy, leaving no documented process for handling vulnerabilities in a validation library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sfire-framework/sfire-http Version 1.0.* | — | — |
sfire-framework/sfire-datacontrol Version >=1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.