Documentation, tests, release notes, and licensing are all in place. Maintenance depends heavily on one contributor, while the release workflow has high-confidence template-injection findings and broad token permissions. The project also lacks a security policy.
67%
Total Score
67
50
100
50
The package declares 41 runtime dependencies, including several framework-specific components and platform extensions; this broad dependency surface increases upgrade and transitive-maintenance burden.
The package runs a post-autoload-dump install-time script. This may be expected for a framework, but it adds execution during installation and therefore some supply-chain and deployment complexity.
The repository is owned by a user account rather than an organization, so the concentrated contribution pattern is not visibly offset by organization-level handoff capacity.
Two contributors were active in the last 3 months, but the top contributor made about 90% of commits, leaving maintenance capacity concentrated despite a second active contributor.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1.4 | — | — |
symfony/yaml Version ^v8.0.0 | — | — |
apereo/phpcas Version >=1.6.2 | — | — |
php-mcp/server Version >=3.3.0 | — | — |
select2/select2 Version ^4.1.0-rc.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.