The release is packaged with tests, a changelog, and a clear README, and its repository matches the package. Its maintenance record is effectively dormant, with no recent releases or commits, no active maintainers, and little visible adoption; avoid relying on it for new work.
35%
Total Score
50
83
50
The package runs a post-create-project-cmd script during installation. This can be normal for a Composer application, but it adds installation-time behavior that should be understood before adoption.
The package is about 7 years old and has had no release in the last 12 months; its latest registry release was on May 6, 2019. This is strong evidence of abandonment for an application framework package.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, consistent with the long release gap. No provided signal shows ongoing maintenance capacity.
The linked repository has 0 stars, 0 forks, and 1 watcher, offering little evidence of an active user or contributor community. Popularity is supporting evidence, but it reinforces the maintenance concern here.
The repository has no security policy, so there is no documented security-reporting path for a package that acts as a full social-network application. The absence adds a transparency concern alongside the stale maintenance record.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.0 | — | — |
yiisoft/yii2 Version 2.0.15 | — | — |
cebe/markdown Version 1.0.2 | — | — |
npm-asset/at.js Version ^1.5.1 | — | — |
firebase/php-jwt Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.