The project has minimal adoption, no recent issue or contributor activity, and no security policy or scanning. Its MIT license, matching repository, clear README, and lack of install scripts provide useful transparency but do not offset the maintenance risk.
34%
Total Score
38
50
78
50
The package has had no release in about 8 years: its latest release was March 2018, despite 11 releases overall. That long gap is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the past 3 months, consistent with the last repository push being about 8 years ago. This is the clearest maintenance and abandonment concern.
The package declares 11 runtime dependencies, including framework, database, mail, image, and deployment components. This creates meaningful dependency maintenance exposure for an otherwise long-unmaintained application starter.
Only one registry account can publish releases. That is normal for an individually owned project, but it leaves little publishing redundancy when combined with the absence of recent activity.
The package and repository are owned by the same individual account, so the source linkage is coherent. There is no organization backing shown to provide additional maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.34 | — | — |
mikecao/flight Version ^1.3 | — | — |
joelvardy/flash Version dev-master | — | — |
robmorgan/phinx Version ^0.8.1 | — | — |
vlucas/valitron Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.