Tests, a clear MIT license, and an unarchived repository improve day-to-day confidence. Maintenance is concentrated in one active contributor, and no security policy is published.
78%
Total Score
83
50
94
75
The release declares 19 runtime dependencies, including a broad set of framework and payment-related components. This adds maintenance surface, but the dependency list is explicit and does not by itself indicate unfitness.
All recent repository commits came from one contributor, creating a real continuity risk. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe risk.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a transparency and hygiene gap, not evidence that the release is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bytic/form Version ^0.9 || ^1.0 || ^2.0 | — | — |
bytic/view Version ^0.9 || ^1.0 || ^2.0 | — | — |
bytic/money Version ^0.9 || ^1.0 || ^2.0 | — | — |
bytic/actions Version dev-main || ^1.0 || ^2.0 | — | — |
psr/http-client Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.