Tests, a clear MIT declaration, and recent releases provide useful support. The large runtime dependency set and missing security policy add operational burden for production adoption.
42%
Total Score
0
50
100
50
The repository recorded 0 commits and 0 active maintainers in the last three months, indicating a meaningful maintenance and abandonment risk despite the recent release timestamp.
The package declares 39 runtime dependencies, creating a broad update and compatibility surface for a framework release. This does not prove a problem, but it increases the maintenance burden.
The linked repository has no published security policy, leaving vulnerability-reporting expectations and response guidance unclear for a framework intended for application use.
The only workflow grants top-level write permissions, all 29 action references are unpinned, and three high-confidence archived-action findings were reported. No untrusted checkout or script-injection sink was found, so this is serious hygiene risk rather than a standalone critical failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^1.57 | — | — |
amphp/redis Version ^2.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
ramsey/uuid Version ^4.9 | — | — |
symfony/yaml Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.