Usable with caveats: the package is licensed, documented, non-deprecated, and backed by a matching repository, but maintenance appears stalled with no release in about 18 months and no recent commits. Its tiny user base, absent tests, and lack of a security policy add ongoing adoption risk.
58%
Total Score
38
50
83
83
There were zero commits and zero active maintainers in the last three months. Combined with the long release gap, this is the strongest indication that maintenance may have stalled.
The package has six runtime dependencies, including an ORM, mailer, templating, environment, and JWT libraries. This is a meaningful dependency surface for a web framework component, though not excessive for the functionality described.
Two registry publishing accounts are listed, both apparently representing the same individual. That provides limited publishing redundancy and leaves a thin maintainer base.
The registry namespace and repository owner match, and the owner is an individual account rather than an organization. This supports ownership continuity but provides limited organizational backing.
The package has 16 releases since March 2023, but it has had no release in about 18 months. That long publishing gap raises maintenance risk despite the earlier release cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rain/raintpl Version 3.0.0 | — | — |
firebase/php-jwt Version ^5.2 | — | — |
vlucas/phpdotenv Version ^5.4 | — | — |
illuminate/database Version ^9.50 | — | — |
phpmailer/phpmailer Version ^6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.