The package is small and easy to inspect, with only two runtime dependencies and no install hooks. Its README documents basic use, but the project shows no commits for about 15 months and only two releases, both issued on the same day. Pin this version only if its limited maintenance meets your needs.
52%
Total Score
25
100
86
75
There were no commits and no active maintainers in the last three months, consistent with maintenance having stopped for about 15 months. This materially increases abandonment risk.
Only two releases were published, both within the same day, and there have been no releases in the last 12 months despite the package being about 15 months old. This is a meaningful maintenance concern, though the small package scope may partly explain the limited cadence.
There were no new or closed issues or pull requests in the last month. With no recent commits, this supports a picture of inactivity rather than active maintenance.
The repository uses Composer, but no security scanning tools are present. The missing scanning is a modest transparency and hygiene gap, not evidence that the release is unsafe by itself.
The repository has no security policy. This weakens the documented process for reporting vulnerabilities, although it does not by itself show that the package is abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version >=6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.