Usable with caveats: this is a newly published package with no demonstrated release or maintenance history yet. The repository is present, licensed, and matches the package, but it has no tests, no security policy, and no recorded commit activity over the last three months.
68%
Total Score
50
100
75
83
A README and changelog are present, but neither the artifact nor the repository contains tests. For a framework core with HTTP, authentication, database, and CLI functionality, the lack of visible tests is a meaningful maturity gap.
The package is 0 days old with only one release, so there is not yet enough history to demonstrate maintenance or release stability. Its stable 1.2.3 version partly offsets this, but does not establish maturity.
No commits or active maintainers were recorded in the last three months. Because the package is newly released, this may reflect its age, but it still leaves ongoing maintenance unproven.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, though it is unsurprising for a package released today and is not decisive by itself.
Composer is used as the build tool, but no security scanning tool is configured. The missing scanning is a transparency gap for a framework core, although it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
phpmailer/phpmailer Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.