Healthy and actively maintained, with strong release activity, complete packaging, and a matching source repository. The main caveats are that one contributor made all recent commits and the repository lacks a security policy and explicit workflow token permissions.
78%
Total Score
83
50
88
70
The package has 15 runtime dependencies covering framework, database, payments, email, and cloud functionality. This is substantial but consistent with a full CMS and increases dependency maintenance exposure.
A post-update-cmd lifecycle script runs during dependency updates, adding some installation complexity and requiring review of its behavior before adoption.
All 85 recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools were detected, leaving less automated coverage for dependency or code risks.
The repository has no security policy, so vulnerability reporting and coordinated response procedures are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 | — | — |
php-di/php-di Version ^7.1 | — | — |
neuron-php/cli Version 0.8.* | — | — |
neuron-php/dto Version 0.0.* | — | — |
neuron-php/mvc Version 0.9.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.