The package includes a README, tests, and release notes, with Composer and Sonar supporting a workable project. Its very short history and absent security policy leave limited evidence of long-term resilience.
68%
Total Score
63
50
94
50
The package declares 17 runtime dependencies spanning framework, database, payment, mail, cache, and image functionality. This is substantial dependency surface for a young project and increases maintenance exposure.
Composer defines post-root-package-install, pre-update-cmd, and post-update-cmd scripts. These are a small supply-chain exposure because package-manager operations execute project-defined commands, though no dangerous behavior is shown here.
Only one account has registry publish access. That is consistent with the linked user-owned project, but it leaves publishing dependent on a single person.
The repository is owned by a user account rather than an organization, so there is no organizational backing to offset the concentrated contributor and publishing base.
The package is only 96 days old but has 40 releases, including 40 in the last 12 months and a median interval of about 15 hours. This shows strong activity but limited evidence of mature, sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.21 | — | — |
filp/whoops Version ^2.18 | — | — |
doctrine/orm Version ^2.17 | — | — |
doctrine/dbal Version ^3.7 | — | — |
predis/predis Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.