The repository is not archived, the package has a clear README, and the organization owns the matching source project. Its four runtime dependencies and lack of security scanning add modest upkeep concerns.
62%
Total Score
75
50
83
83
Four runtime dependencies, including Guzzle and three Tigron packages, create a moderate upkeep surface and add transitive dependency exposure.
The package has existed since January 2019 with 10 releases, but it had no releases in the last 12 months and was last released in June 2025. This indicates slowing maintenance rather than abandonment by itself.
There were zero commits and zero active maintainers in the last three months. Combined with no releases in the last 12 months, this is the main evidence of currently quiet maintenance.
The repository has zero stars and forks and four watchers. This is weak supporting evidence, though popularity is not decisive for a small organization-backed package.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a modest transparency and upkeep gap, not proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~7 | — | — |
tigron/skeleton-object Version >=0.1.22 | — | — |
tigron/skeleton-migrate Version >=0.1.9 | — | — |
tigron/skeleton-database Version >=0.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.