Integration should be straightforward for consumers. The package includes tests, release notes, documentation, and a clear license, but its maintenance continuity is uncertain and security-process coverage is limited.
46%
Total Score
25
75
50
The latest registry release was in March 2020, with no releases in the last 12 months despite the package being over 10 years old. This is strong evidence that release maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last 3 months. Together with the stale registry release history, this indicates a substantial abandonment risk.
There were no new or closed issues and no merged pull requests in the last month, while 11 issues and 9 pull requests remain open. This suggests little recent project stewardship.
Composer build tooling is present, but no security scanning tools were detected. This weakens automated security hygiene, though it is not by itself evidence that the release is unsafe.
The repository has no security policy, leaving no documented process for reporting vulnerabilities. This is a meaningful but secondary transparency gap for a package with otherwise clear source and licensing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mnapoli/silly Version ~1.0 | — | — |
illuminate/view Version 5.*|^6.0|^7.0 | — | — |
mnapoli/front-yaml Version ^1.5 | — | — |
windwalker/renderer Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.