Its MIT license, coherent package tree, and organization-owned repository provide basic transparency. The tiny, untested project has no recent activity, so pinning it carries substantial abandonment risk.
35%
Total Score
63
100
61
83
The latest release was published in April 2017, with no releases in the last 12 months. That long release gap is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push being in 2017. This materially increases abandonment risk.
A README and changelog are present, but the README explicitly says this was an initial commit and had not been tested. The absence of packaged tests is normal and is not treated as a gap by itself.
There are no open issues or pull requests and no recent issue or pull-request activity. While this may reflect a small project, it provides no evidence of ongoing maintenance.
The repository has zero stars and forks and only three watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of adoption or external validation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slaxweb/config Version ~0.3 | — | — |
symfony/http-foundation Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.