The package is small and its consumer documentation is available. Its install hook and lack of security tooling add operational risk.
38%
Total Score
50
100
71
50
The package has had no release in over three years and no releases in the last 12 months, indicating substantial abandonment risk despite having three releases overall.
Neither the package nor the linked repository provides a declared or detected license, so developers lack clear permission to use and redistribute the code.
A post-install command runs during installation, adding setup-time behavior that should be understood before adoption; no compensating security or maintenance evidence is provided.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving maintenance capacity uncertain.
Composer is used for the build, but no security scanning tools are present, leaving dependency or source issues less likely to be detected automatically.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^8 | — | — |
topthink/think-view Version ^2 | — | — |
topthink/think-helper Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.