The BSD-3-Clause licensing is clear, installation has no lifecycle scripts, and this version has published release notes. Its single runtime dependency keeps the footprint modest, but the project lacks security scanning and has no automated workflow coverage.
38%
Total Score
0
100
58
100
Only two releases were published, both in July 2020, with no release in roughly six years. That sharply raises abandonment and compatibility risk for a dependency.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and limited evidence of ongoing maintenance.
The artifact has no README, tests, or changelog, which limits consumer guidance and verification. The exact version does have GitHub release notes, partly compensating for the missing changelog.
Composer build tooling is present, but no security-scanning tooling was detected. That is a transparency and hygiene gap, not a standalone reason to reject the package.
Version 0.2.1 is not a prerelease, but the 0.x major version and absence of subsequent releases indicate an immature, effectively stalled API line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
goaop/framework Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.