The MIT license, matching repository, and release notes improve transparency. The short README, install hook, and absent security policy leave important maintenance and integration gaps.
51%
Total Score
50
67
50
The latest release was in November 2023, with no releases in the last 12 months despite eight releases overall. This indicates prolonged release inactivity for a package consumers may need to maintain.
The package runs a post-autoload-dump install-time script, adding execution during dependency installation. No provided signal shows that this hook is unnecessary or narrowly scoped.
A README is present and the v0.0.8 release includes release notes, which helps transparency. However, the README is only 22 characters long and provides little integration guidance.
The repository had zero commits and zero active maintainers in the last three months. Its last push was in April 2024, so recent maintenance evidence is weak.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tina4stack/tina4php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.