Documentation, tests, and a GitHub release are present, but the project offers little evidence of current support. The repository does not identify this package, and its build includes install-time scripts without a security policy.
35%
Total Score
0
50
57
50
This is the only release, published about 7 years and 10 months ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
There were no commits and no active maintainers in the last 3 months. This is strong evidence that maintenance has stopped or is currently inactive.
The package declares 16 runtime dependencies spanning HTTP, WebSocket, Redis, database migration, and application infrastructure. That breadth increases maintenance burden compared with a small library.
Post-install and post-update scripts run during dependency operations. These increase installation complexity and execution exposure, though the signal alone does not establish that the scripts are unsafe.
The linked repository name does not match the package name and its README does not mention the package. That raises concern that the repository may not actually be the package's source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/log Version ^1.0 | — | — |
amphp/artax Version ^3.0 | — | — |
amphp/redis Version ^0.3.3 | — | — |
filp/whoops Version ^2.2 | — | — |
cocur/slugify Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.