Its documentation, tests, licensing, and dependency setup give consumers a clear starting point. Maintenance rests entirely with one contributor, and the repository has no security policy or security-scanning tooling.
68%
Total Score
63
100
94
83
Only one registry account has publish access. That is consistent with a small project, but it leaves release publishing dependent on a single person.
The repository is owned by an individual account rather than an organization. Combined with the single-contributor activity, this provides no organizational handoff signal.
One contributor made all 32 commits in the last three months, giving the project a complete single-person bus factor. Recent activity is encouraging but does not compensate for the continuity risk.
Composer is used as a build tool, but no security-scanning tooling is present. For a package intended to be used as an application framework, this is a meaningful security-process gap.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.10 | — | — |
raymondoor/migrr Version ^0.5.1 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.