The package has a small, focused codebase and normal Composer packaging. Maintenance evidence is limited by no commits in three months, no tests, no README, and no security policy. Its stable version and active release burst provide some offset.
55%
Total Score
50
71
50
The artifact and repository have no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but a missing README is a real integration gap for this library.
All 12 releases were published on the same day, 59 days ago, so the package has release activity but no demonstrated ongoing cadence.
There were no commits and no active maintainers in the last three months, which is a meaningful warning for a package only 59 days old.
The repository has zero stars, forks, and watchers, providing no supporting evidence of external adoption or review; this is supporting evidence rather than a verdict.
Composer is used for builds, but no security scanning tool is present. That is a modest repository-hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.