The MIT license, tests, and package-specific repository provide basic transparency and make the code easier to inspect. Its single open issue, zero recent contributors, and lack of security policy leave little evidence of ongoing care.
34%
Total Score
50
70
50
The package has made only three releases, all clustered in January 2016, and none in roughly 10 years. That release history is strong evidence of abandonment for a dependency expected to receive maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long-stalled release history. No provided signal compensates for this lack of current activity.
One issue remains open, with no issues or pull requests opened or closed in the last month. This is a modest maintenance concern rather than a severe risk by itself.
The repository has zero stars, one fork, and one watcher, providing little supporting evidence of a broad user or maintainer community. Popularity is only supporting evidence, so this reinforces rather than determines the abandonment concern.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap, especially for an old package with no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
robmorgan/phinx Version 0.* | — | — |
slimphp-api/slim-api Version 0.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.