The repository is active enough to remain available, is organization-backed, and matches the package. Documentation and security safeguards are thin, with no README, security policy, or repository scanning; recent release activity partly offsets the lack of commits in the last three months.
68%
Total Score
75
88
75
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a published package artifact, but the absent README is a minor consumer-documentation gap for a testing library.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the 23 releases in the last year provide compensating evidence of recent package activity.
Composer is used for builds, but no security-scanning tooling is reported. This is a modest transparency and protection gap, not evidence that the package is unsafe.
The repository has no security policy. That leaves vulnerability-reporting and response expectations unclear, which modestly lowers project transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mantle-framework/http Version ^1.0 | — | — |
mantle-framework/faker Version ^1.0 | — | — |
mantle-framework/support Version ^1.0 | — | — |
mantle-framework/database Version ^1.0 | — | — |
mantle-framework/contracts Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.