The BSD-3-Clause license and minimal Composer-only setup are clear, while organization backing provides some accountability. Its narrow testing-setup role may limit exposure, but ongoing maintenance cannot be assumed.
38%
Total Score
50
72
75
The package has only one release, published nearly nine years ago, with no releases in the last 12 months. That strongly raises abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and weak evidence of ongoing maintenance.
The repository name matches the package name, so there is no evidence that the package is piggy-backing on an unrelated project. The README does not mention the package, which is a minor transparency gap.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but this provides little supporting evidence of active community use or review.
Composer is used as the build tool, but no security-scanning tooling is reported. For this small Composer setup package, that is a hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neam/php-app-config Version dev-develop | — | — |
neam/yii-dna-pre-release-testing Version dev-develop@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.