Tests are present and installation has no lifecycle scripts, but the README is only a 17-character heading. The sole release and last repository push were over nine years ago, leaving substantial maintenance risk for a new dependency.
38%
Total Score
0
100
60
75
This package has only one release, published over nine years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the stable version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and providing no evidence of current maintenance.
Tests are included in both the package and repository, and a GitHub release exists for this version. The README is only 17 characters and there is no changelog, so consumer documentation is weak, though the tests provide some maturity evidence.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are present, a minor transparency gap that does not outweigh the severe maintenance concern.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but it is secondary to the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.1 | — | — |
silex/silex Version 2.0.x-dev | — | — |
symfony/css-selector Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.