The project has a recent release, a long release history, and an active organization-owned repository. No commits in the last three months, no automated security scanning, and no tests create maintenance and assurance concerns.
68%
Total Score
75
50
93
100
The framework declares 16 runtime dependencies and no development dependencies, making the runtime dependency surface relatively broad and leaving little visible separation between runtime and development requirements.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning despite the recent release and non-archived repository.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated assurance for a framework with a substantial runtime dependency set.
No GitHub Actions workflows were found, so there are no detected workflow trigger, permission, or action-pinning hazards. This also means no workflow automation was available to provide build or security assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.18 | — | — |
symfony/console Version ^7.4 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
bayfrontmedia/veil Version ^2.1 | — | — |
bayfrontmedia/route-it Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.