Its packaging is straightforward and the source is easy to identify. The project has tests and organization backing, but no commits in three months and only one release in the last year make ongoing support less certain.
68%
Total Score
75
100
88
83
The package has existed for over seven years and has 17 releases, but only 1 release appeared in the last 12 months. This indicates a mature history with currently limited release activity.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent release partly offsets this but does not show continued activity.
Composer build tooling is present, but no security-scanning tooling was detected. The build setup is established, while the absent scanning is a modest hygiene limitation.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is not severe enough to outweigh the maintenance and packaging evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bytic/config Version ^0.9|^1.0|^2.0 | — | — |
bytic/dotenv Version ^4.0|^5.0 | — | — |
bytic/console Version ^0.9|^1.0|^2.0 | — | — |
bytic/container Version ^0.9|^1.0|^2.0 | — | — |
robmorgan/phinx Version ~0.13|~0.14|~0.15|~0.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.