The stable major release, MIT licensing, tests, and matching organization-owned repository provide a solid foundation. Its documented structure is clear, but the lack of recent project activity and security documentation limits confidence in continued maintenance.
58%
Total Score
67
88
75
The package has 50 releases since October 2013, but none in the last 12 months and the latest release was over five years ago. This long release gap is a meaningful maintenance concern despite the historically regular 13-day median interval.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for several years. This materially raises the risk that defects and compatibility issues will remain unaddressed.
The repository has 14 open issues, with no new or closed issues and no pull-request activity in the last month. This is supporting evidence of limited current maintenance, though the short observation window makes it less decisive than the commit history.
The repository uses Composer for builds, showing basic build structure, but it reports no security-scanning tools. The missing scanning layer is a modest transparency and maintenance gap.
No security policy is present in the repository. For a framework skeleton with web-facing application code, that weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
public/jquery Version dev-master | — | — |
public/require Version dev-master | — | — |
twbs/bootstrap Version ~5.0 | — | — |
bluzphp/bluzman Version ~2.5 | — | — |
robmorgan/phinx Version ~0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.