Documentation is brief, while the package includes tests and a clear MIT license. Frequent releases and recent repository work show ongoing maintenance, but the project lacks security scanning and a security policy.
70%
Total Score
75
50
94
75
The framework declares 25 runtime dependencies, creating a broad transitive dependency surface that increases maintenance and upgrade burden compared with a smaller library.
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
One contributor made 100% of the 38 recent commits, leaving the project exposed to a single-person maintenance failure despite the recent activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a meaningful repository hygiene gap for a framework with many runtime dependencies.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.5 | — | — |
filp/whoops Version ^2.15 | — | — |
nette/utils Version ^4.0 | — | — |
pecee/pixie Version ^4.15 | — | — |
symfony/yaml Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.