Package Health

forme/framework

An MVC framework for WordPress.

Latest v4.2.1PackagistPackagist

68%

Total Score

caution

Usable with caveats: strong release and project documentation, but no commits in three months and weak workflow security hygiene.

Health Score Breakdown

Dependency profilecaution

The package declares 23 runtime dependencies for a framework, creating meaningful transitive maintenance exposure, though the profile is consistent with its broad framework role.

Lifecycle scriptscaution

A post-install command runs during installation, adding execution-time supply-chain exposure beyond ordinary package extraction; no provided signal shows that this script is unsafe.

Maintainerscaution

Only one registry account has publishing access, which is a resilience concern, although the repository is owned by an organization and release activity is substantial.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which conflicts with the otherwise strong release history and raises concern about current maintenance depth.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool is reported, leaving a security-process gap for a framework with many runtime dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Moussa Clarke

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.14
—
—
ramsey/uuid
Version ^4.7.4
—
—
relay/relay
Version ^3.0
—
—
spatie/enum
Version ^3.13
—
—
cakephp/core
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform