Mini framework
52%
Total Score
caution
One release, no commits in three months, and a single maintainer make ongoing maintenance uncertain.
Only one registry maintainer account is listed, leaving limited visible publishing redundancy for a package that is not organization-backed.
The repository is owned by an individual user rather than an organization, so there is no organizational backing shown to offset the single-maintainer and inactive-commit concerns.
This package is 204 days old but has only one release, so there is little release history to demonstrate sustained maintenance or responsiveness.
The repository had zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package released only once.
Composer is used as a build tool, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.