The artifact is compact and clearly licensed, but installation runs a post-install command and the repository has no security policy or scanning. Its stable version and non-archived source help, though ongoing support remains limited.
55%
Total Score
50
88
67
A post-install command runs during installation, adding execution behavior that consumers must trust beyond ordinary file installation.
One registry maintainer creates a thin publishing base; the user-owned repository provides no strong organizational backing to compensate for that concentration.
Only three releases exist, with the latest published in March 2023 and none in the last 12 months; this indicates prolonged maintenance inactivity.
The repository recorded no commits and no active maintainers in the last three months, reducing evidence of current maintenance capacity.
Composer is used for the build, but no security scanning tools are present; this is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0 | — | — |
topthink/think-view Version ^1.0 | — | — |
topthink/think-helper Version ^3.0.0 | — | — |
topthink/think-multi-app Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.