Its MIT licensing and matching repository make provenance and reuse straightforward. The very small public footprint and missing security policy add practical uncertainty for a framework.
38%
Total Score
50
63
75
The latest release was published on May 10, 2021, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a framework dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus. The organization-owned repository provides context but does not compensate for absent recent work.
The package includes a README and has a GitHub release for this version. No tests or changelog are not gaps in the published artifact, though the README is only 105 characters for a framework package.
The repository has only 2 stars, 0 forks, and 2 watchers. Popularity is not decisive, but this very small footprint provides little supporting evidence of broad adoption or review.
Composer is used for builds, but no security scanning tools are configured. That reduces ongoing supply-chain hygiene for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psy/psysh Version ^0.10 | — | — |
prinx/dotenv Version ^0.4 | — | — |
prinx/notify Version ^0.0 | — | — |
prinx/os-utils Version ^0.0 | — | — |
prinx/phputils Version ^0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.