The repository has no security policy or automated security scanning. MIT licensing, a clear 4,632-character README, and only three runtime dependencies improve transparency, but the project remains early-stage.
58%
Total Score
50
100
81
50
The package is only 127 days old and has just two releases, with the latest released about four months ago. This provides limited evidence of a settled maintenance process.
The repository recorded zero commits and zero active maintainers in the last three months. That indicates a recent pause in development despite the repository not being archived.
Composer build tooling is present, but no security-scanning tools were detected. For a PHP framework that handles application infrastructure, this is a meaningful hygiene gap.
The repository has no security policy. This weakens transparency and gives consumers no stated process for reporting or handling vulnerabilities.
Version v0.0.2 is not a stable major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which provides only limited compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
scssphp/scssphp Version ^1.13 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.