The MIT license, tests, release notes, and matching source repository provide useful baseline transparency. A single publishing account, no security policy or scanning, and negligible repository adoption add ongoing maintenance risk.
42%
Total Score
50
50
63
50
Only two releases exist, both clustered in February 2025, and there were no releases in the last 12 months. That short history and prolonged release gap indicate a potentially abandoned beta project.
There were no commits and no active maintainers in the last three months, while the latest repository push was about 19 months ago. This is the clearest maintenance and abandonment concern in the assessment.
The package has 14 runtime dependencies, including framework, database, authentication, logging, and environment components. This is a substantial dependency surface for a beta framework and increases maintenance exposure, though it is not extreme by itself.
Only one registry publishing account is listed. The repository is organization-owned, which provides some backing, but the observed publishing base remains thin.
The package includes a README, tests, changelog, and release notes for this version, which supports consumer guidance and release traceability. The README excerpt appears unrelated to this framework, reducing confidence in the documentation signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
php-di/php-di Version ^7.0 | — | — |
monolog/monolog Version ^3.8 | — | — |
firebase/php-jwt Version ^6.11 | — | — |
jenssegers/blade Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.