Recent releases and a complete, tested package provide useful continuity. The repository had no commits or active maintainers in the last three months, and all three workflow actions are unpinned; no security scanning or policy is visible.
64%
Total Score
75
86
50
The package defines post-autoload-dump and post-root-package-install scripts. Install-time execution increases dependency-installation exposure, although the signal alone does not show that these scripts are unsafe.
The repository recorded zero commits and zero active maintainers during the last three months. Although a January 2026 release exists, the recent lack of development lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. For a framework package this is a meaningful hygiene gap, though it is not evidence of a vulnerability.
The repository has no security policy. This weakens vulnerability-reporting transparency and maintainer response expectations, but does not by itself make the release unfit.
Version 0.2.2 is not a prerelease, but the package remains below a stable major version. That signals some API-change risk without indicating abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
next/di Version ^0.2.0 | — | — |
next/utils Version ^0.2.0 | — | — |
next/routing Version ^0.2.0 | — | — |
monolog/monolog Version ^3.10.0 | — | — |
next/http-server Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.