There is no security policy, and installation runs post-install and post-update scripts. The package is licensed and documented, but its source has had no commits since April 2018.
38%
Total Score
0
83
50
The latest release was published in April 2018, and there have been no releases in more than 8 years. The three-release history shows an early project, but not continuing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating a strong abandonment risk.
The package runs post-install and post-update Composer scripts, so dependency operations execute package-provided code. That is not inherently unsafe, but it increases the importance of active maintenance and transparent release practices.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap to an already inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
agentmedia/phine-core Version * | — | — |
agentmedia/phine-news Version * | — | — |
agentmedia/phine-forms Version * | — | — |
agentmedia/phine-builtin Version * | — | — |
agentmedia/phine-framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.