The repository is small and has no security policy, although the README and MIT declaration are useful. Its single stable release is documented, but the lack of recent commits leaves maintenance capacity unproven.
43%
Total Score
0
75
50
Only one release exists, published about 20 months ago, with no releases in the last 12 months. This is strong evidence of limited maintenance for a framework dependency.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was about 17 months ago. The repository is not archived, but this inactivity still raises abandonment risk.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these counts provide little evidence of external review or adoption.
The project uses Composer for builds, providing basic ecosystem-appropriate tooling, but it has no detected security scanning. This is a minor positive with limited assurance value.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a web framework handling authentication, requests, and mail.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tracy/tracy Version ^2.10 | — | — |
eftec/bladeone Version ^4.16 | — | — |
delight-im/auth Version ^8.3 | — | — |
hashids/hashids Version ^5.0 | — | — |
erusev/parsedown Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.