43%
Total Score
unhealthy
Risky: stagnant releases and a version mismatch make this release hard to trust for new dependencies.
The package is about 3 years 7 months old, has only two releases, and has had no release in the last 12 months. This is strong evidence of limited maintenance, although the linked repository was pushed more recently.
The package runs a post-install-cmd script, which increases installation complexity and gives package code execution during installation. No compensating security or provenance signal was provided.
There were no commits and no active maintainers in the three months measured. Despite the repository's more recent push, the observed current activity is weak.
Composer build tooling is present, but no security scanning tools were detected. This is a modest repository hygiene gap rather than evidence of unfitness by itself.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, with no provided evidence compensating for the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
forme/framework Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.