The package is well documented and tested, with a substantial source tree and no install scripts. Its license metadata conflicts with the included license file, and no security policy or automated scanning is visible.
61%
Total Score
75
50
75
75
Ten runtime dependencies make the framework meaningfully dependent on a broad upstream surface, increasing maintenance exposure, though the profile is not extreme for a web framework.
A license file is present, but the manifest declares BSD-4-Clause while the artifact and repository file are recognised as BSD-3-Clause. The mismatch creates a transparency concern despite the package being licensed.
The package has 271 releases over about five years, but only 2 in the last 12 months; the latest release is recent, so this indicates slowing maintenance rather than abandonment.
The repository recorded zero commits and zero active maintainers over the last 3 months. This conflicts with the recent push and recent release, but still indicates limited observed development activity.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish that this repository publishes this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mrclay/minify Version 3.0.* | — | — |
rybakit/msgpack Version 0.8.* | — | — |
tarantool/client Version 0.9.* | — | — |
vlucas/phpdotenv Version ^2.4.0 | ^5.4.1 | — | — |
phpoffice/phpword Version 1.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.