The small project has no recent commit activity and lacks security scanning or a security policy. It is not deprecated or archived, has a current stable release, and includes a focused package tree with usable documentation.
68%
Total Score
50
100
94
88
A single registry maintainer limits publishing redundancy, but the linked repository is owned by the same individual and recent release activity provides some compensation.
The package and repository are consistently owned by the same individual rather than an organization, so the single-maintainer concern is not offset by organizational backing.
There were no commits and no active maintainers in the last three months, which is a concrete maintenance concern even though a release was published during the broader 12-month period.
The repository has four open issues and one open pull request, with no issues or pull requests opened or merged in the last month; this suggests limited current project interaction.
Composer is used as the build tool, but no security scanning tools are configured, leaving a meaningful repository hygiene gap for dependency maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^8.0 | — | — |
topthink/think-view Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.