The package has a clear README, matching source repository, MIT licensing, and a small dependency surface. Its only release was over five years ago, with no recent commits or release activity, making abandonment a substantial concern.
42%
Total Score
25
100
78
50
This package has only one release, published over five years ago, with no releases in the last 12 months. That is strong evidence of limited maintenance for a dependency intended for ongoing framework use.
There were no commits and no active maintainers in the last three months, consistent with the repository's last push being over five years ago. This materially raises abandonment risk.
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not have organizational backing to compensate for the lack of recent activity.
The repository has one star and no forks, providing little evidence of community adoption or an external support base. Low popularity is supporting caution rather than a verdict by itself.
The repository uses Composer, which fits the package ecosystem, but it has no security-scanning tools. That is a modest transparency and maintenance gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.