It includes tests, a substantial README, and no install-time scripts. Credential-named files, zero repository stars, and no security policy provide little independent assurance.
42%
Total Score
60
67
The package has only one release, published about 3 years ago, with no releases in the last 12 months. That gives little evidence of ongoing maintenance for a dependency.
The package contains files named client_secret.json and credentials.json alongside application code. Even without proving misuse, including credential-named files is poor release hygiene and raises adoption risk.
The repository name matches the package, but its README does not mention the package and instead describes a Slim Framework application. This weakens confidence that the published package is clearly maintained from the linked project.
The repository has zero stars and zero forks, offering no community adoption signal. This is supporting evidence only, so it reinforces the broader lack of assurance rather than deciding the score alone.
The repository has no security policy. That is a transparency and maintenance gap for a package intended to handle application code and dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
klein/klein Version ^2.1 | — | — |
catfan/medoo Version ^2.1 | — | — |
bramus/router Version ^1.6 | — | — |
doctrine/dbal Version ^3.1 | — | — |
crunzphp/crunz Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.