The README, MIT declaration, and matching organization-owned repository provide useful transparency. Install-time scripts and the broad runtime dependency set add maintenance and adoption risk.
45%
Total Score
50
50
86
50
The package has 38 releases, but none in the last 12 months; its latest release was in April 2023, roughly three years ago. The earlier cadence does not compensate for this prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of current maintenance.
Eleven runtime dependencies, including framework, database, templating, encryption, and caching components, create a comparatively broad dependency surface for a small framework. No development dependencies or other provided evidence materially offsets that maintenance burden.
The package runs post-install and post-update Composer scripts, adding execution and maintenance complexity for consumers. No provided signal shows these scripts are necessary or narrowly scoped.
The linked repository has no security policy. This is a transparency gap for a framework that handles application requests, sessions, encryption, and database access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.5 | — | — |
catfan/medoo Version ^2.1 | — | — |
league/climate Version ^3.2.1 | — | — |
monolog/monolog Version ^3.3 | — | — |
sincco/tokenizer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.