Usable with caveats: it has a long release history, tests, release notes, and an active-looking repository, but the latest release was nearly two years ago and recent commit activity is absent. A single registry maintainer and no security policy add maintenance and transparency risk.
62%
Total Score
38
50
81
83
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
Ten runtime dependencies, including framework and database-related packages, create a meaningful dependency surface for a PHP framework, though the signal does not show an excessive or clearly unsafe profile.
Only one account has registry publish access, leaving the release process dependent on a single publisher. This is a maintenance-resilience concern, although registry access records do not establish actual development activity.
The repository is owned by an individual user rather than an organization, so the single-publisher and small-footprint concerns are not offset by visible organizational backing.
The package has 433 releases since 2015, showing substantial historical maintenance, but it has had no releases in the last 12 months and the latest release was nearly two years ago.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version 2.* | — | — |
robmorgan/phinx Version ^0.13.4 | — | — |
josegonzalez/dotenv Version 3.* | — | — |
pecee/simple-router Version ^5.0 | — | — |
laravel/serializable-closure Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.