Its MIT license and simple Composer build reduce adoption friction. Maintenance evidence is weak, with no activity since November 2024, only two releases, and one registry maintainer; documentation and security oversight are also limited.
42%
Total Score
33
100
72
83
The package has only two releases, both made on November 12, 2024, and none in the last 12 months. This leaves little evidence of continuing maintenance for a package now nearly two years old.
There were zero commits and zero active maintainers in the last three months, consistent with an inactive project nearly two years after its last release. This materially raises abandonment risk.
Only one account has registry publish access. The linked repository is user-owned rather than organization-backed, so there is little visible publishing redundancy if that maintainer becomes unavailable.
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. The missing README is a real documentation gap for a library that consumers must integrate, though absent tests and changelog files are not expected in every published artifact.
The source repository is owned by an individual user, not an organization. This does not prove abandonment, but it provides less visible continuity than organization-backed maintenance when combined with inactive commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1||^2.0 | — | — |
webman/think-orm Version ^1.0 | — | — |
phpseclib/phpseclib Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.