The clear license, matching source repository, and release notes improve transparency. Maintenance evidence is thin, with no recent commits, one publisher, and no security policy.
60%
Total Score
50
100
83
67
The package defines three Composer lifecycle hooks, including post-create and post-update actions. These can change project state during installation or updates, so they add a modest transparency and reproducibility concern.
Only one account has publishing access. Because the repository is owned by an individual rather than an organization, this represents a real concentration of publishing and maintenance capacity.
The registry namespace and repository are owned by the same individual account. That confirms ownership alignment, but it also provides no organizational backing to offset the single-maintainer concern.
The package has three releases over about 16 months, with one release in the last 12 months and a median interval of about 102 days. This shows some release continuity but limited maturity and a slow cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the roughly nine-month gap since the latest release, this is meaningful evidence of currently quiet maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
blitz-php/framework Version ^0.12 | — | — |
dimtrovich/blitzphp-vite Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.