Open source framework for PHP applications. Includes MongoDB modelling system.
78%
Total Score
healthy
Healthy, with steady releases and active organization-backed maintenance outweighing prerelease and workflow-hygiene concerns.
The framework declares 32 runtime dependencies across authentication, database, cloud, and web tooling; this is a broad dependency surface that increases upgrade and compatibility burden.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest process gap for a framework with a broad dependency surface.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
This release is a prerelease, which adds some compatibility uncertainty, although it is the latest version and prereleases are only 20% of recent releases.
The only workflow was fully analyzed, uses read-only permissions, and has no audited findings or untrusted-code sinks. However, all 4 action references are unpinned, creating a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.6 | — | — |
lcobucci/clock Version ^2.0 | — | — |
symfony/dotenv Version ^7.1 | — | — |
mongodb/mongodb Version ^2.1 | — | — |
monolog/monolog Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.