The MIT license, README, repository tests, and exact package mention provide useful transparency and adoption context. The organization-backed repository is not archived or deprecated, but its maintenance has effectively stopped, making long-term fixes and compatibility uncertain.
42%
Total Score
50
50
79
75
The package has had no release in over nine years, despite 12 releases overall; the long period without a new release is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing that active development has stopped.
Six runtime dependencies create some compatibility and maintenance surface, including routing, HTTP, container, and invocation components; this is a moderate concern for an unmaintained package.
The repository uses Composer, but it has no reported security-scanning tooling, leaving a modest transparency and maintenance gap.
No security policy is present, which leaves vulnerability-reporting expectations unclear; this is more concerning because the project has not been maintained for years.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aura/router Version ^3.0 | — | — |
psr/container Version ^1.0 | — | — |
stratify/http Version ~0.5.0 | — | — |
php-di/invoker Version ^2.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.