The project has little evidence of ongoing care, and its README describes a different framework rather than this package. The license mismatch and absent security practices add transparency concerns, despite the repository remaining available and correctly named.
32%
Total Score
75
50
50
83
This package has only one release, published in August 2018, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The package declares 21 runtime dependencies, including several application-specific packages and framework components. This creates meaningful maintenance coupling for an unreleased application package, though no dependency failure is shown.
The artifact contains a license file, but it identifies BSD-3-Clause while the manifest declares MIT. The package is licensed, yet the mismatch creates avoidable legal and transparency uncertainty.
A README and changelog are present, but the README describes zend-expressive rather than this administration package. The missing tests are normal for a published artifact and are not a concern by themselves.
The repository has no open issues or pull requests and no activity in the last month. With only one historical release, this provides no evidence of an active user or maintainer community.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.2 | — | — |
psr/container Version ^1.0 | — | — |
psr/http-message Version ^1.0.1 | — | — |
fig/http-message-util Version ^1.1.2 | — | — |
fearthec/ftc-discord-model Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.