The source is still available and clearly matches the package, with tests and a changelog present. Its small organization-backed project has no security policy, and the bundled license texts do not align cleanly with the MIT declaration.
58%
Total Score
75
80
50
The package declares MIT and includes license files, but detected bundled license texts include MPL-1.1, GPL-2.0, and LGPL-2.1. These may belong to included third-party assets, but the declaration does not cleanly cover the observed texts.
The latest release was published about 5 years ago, and there were no releases in the last 12 months. This materially raises abandonment and compatibility risk despite a stable release history.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although it was pushed more recently than the registry release, current maintenance activity is not evident.
The linked repository has no security policy. For a web-application framework containing authentication and administrative components, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 1.* | — | — |
doctrine/orm Version 2.4.4 | — | — |
doctrine/dbal Version 2.5.4 | — | — |
leafo/lessphp Version 0.4.* | — | — |
bordoni/phpass Version 0.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.