The package has a clear MIT license, repository tests, and a minimal dependency surface. Its single-maintainer project lacks security scanning and a security policy, while recent repository activity has paused; long-term assurance is limited.
70%
Total Score
50
83
83
The package has existed since November 2021 with 14 releases and a latest release in December 2025, but only one release occurred in the last 12 months.
There were no commits or active maintainers in the last three months. The recent release partly offsets this, but the lack of ongoing source activity raises maintenance risk.
The repository has zero stars and forks and only one watcher. This is supporting evidence of a very small project, but not by itself evidence that the package is unsafe to use.
Composer build tooling is present, but no security scanning tool is configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, so it provides no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bearframework/bearframework Version 1.* | — | — |
ivopetkov/client-packages-bearframework-addon Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.