It is clearly licensed and the source repository still matches the package. Maintenance evidence is thin, with no recent commits or releases and no security policy.
18%
Total Score
50
70
50
Packagist marks the entire package as abandoned and explicitly names zxin/think-env as the replacement. This is a direct warning against taking a new dependency on this release.
The package has only 7 releases since June 2020, and it has had no release in the last 12 months; its latest release was about 18 months ago. This supports the abandonment concern.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the stale release cadence, this indicates little current maintenance capacity.
The linked repository has no security policy. For a package that loads environment configuration, this reduces transparency around how security issues should be reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oscarotero/env Version ^2.1 | — | — |
vlucas/phpdotenv Version ^5.5 | — | — |
topthink/framework Version ~6.1.3|~8.0.1|~8.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.