Framework for PHP 7.1+
38%
Total Score
unhealthy
Risky: releases stopped in 2019 and repository activity has effectively ceased.
The package has 425 releases since 2016, but none in the last 12 months and the latest release was about 6 years and 9 months ago. The long earlier history shows maturity, but the prolonged release gap is strong abandonment evidence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This confirms that the old release history is not being followed by current development.
The package defines post-autoload-dump, post-create-project-cmd, post-install-cmd, and post-update-cmd scripts. Install-time behavior increases dependency and review risk, though the signal alone is not evidence of unsafe behavior.
Composer is used as the build tool, which is appropriate for this PHP package, but no security scanning tools are configured. This is a meaningful hygiene gap for a framework with substantial runtime dependencies.
The repository is not archived, which is a modest positive and leaves open the possibility of future maintenance. Its last push was about 5 years and 8 months ago, so this does not offset the inactive commit record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.1 | — | — |
ramsey/uuid Version ~3.0 | — | — |
dompdf/dompdf Version ^0.8 | — | — |
twbs/bootstrap Version ^3.3 | — | — |
google/recaptcha Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.