The package has a clear MIT license, tests, a changelog, and an organization-backed repository that matches the package. Its small audience, absent security policy, and post-update script reduce confidence for long-term use.
60%
Total Score
50
83
67
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the long release pause. This is the strongest evidence of current maintenance risk.
The package defines a post-update-cmd lifecycle script, which adds install-time behavior that should be understood before adoption. The signal does not show that the script is harmful, so this is a limited hygiene concern.
The package has 65 releases over about 6 years, but none in the last 12 months; its latest release was about 16 months ago. This indicates a meaningful maintenance slowdown despite a previously regular median interval of about 28 days.
The repository has 0 stars and 0 forks, with 1 watcher, so there is little visible external adoption or review. Popularity is supporting evidence only, but this provides little compensating assurance for the maintenance gap.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a moderate transparency gap, not evidence of a vulnerability by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
miaoxing/app Version ^0.10.11 | — | — |
miaoxing/link-to Version ^0.1.64 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.