The package includes tests, a README, and a matching MIT license, while its repository is not archived and was pushed recently. Its two-release history, zero commits in the last three months, absent security scanning, and seven unpinned workflow actions leave maintenance and build hygiene concerns.
58%
Total Score
67
79
67
Only two releases have been published over about 14 months, with one release in the last 12 months and a median interval of about 14 months. This indicates a thin release track and lowers confidence in ongoing maintenance.
The repository had zero commits and zero active maintainers in the last three months. Despite the recent push recorded by repository_archived, this is a meaningful sign of currently limited maintenance activity.
There are four open issues, with no issues or pull requests opened or closed in the last month. This gives little evidence of active issue handling.
The project uses Composer, but no security scanning tools were detected. The missing security tooling is a maintenance and transparency concern, though it does not by itself make the release unfit.
The repository has no security policy. For a framework that handles Telegram bot integrations, this weakens the project's vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^3.0 | — | — |
react/http Version ^1.9.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
react/cache Version ^1.2 | — | — |
opis/closure Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.