The README documents installation and configuration, and the repository clearly matches the package. An install-time script and no security policy add maintenance and transparency concerns.
42%
Total Score
50
90
50
A post-install-cmd script runs during installation, adding execution-time supply-chain exposure. No provided signal shows that this script is necessary or narrowly scoped.
This package has only one release, published in February 2023, with no releases in the following three years and seven months. That strongly suggests abandonment, although the repository is not archived.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating no recent maintenance capacity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The small package and matching repository provide some transparency but do not replace that guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0 | — | — |
topthink/think-view Version ^1.0 | — | — |
topthink/think-helper Version ^3.0.0 | — | — |
topthink/think-multi-app Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.