Organization backing, a clear license, and a matching source repository provide useful transparency. The small artifact, missing repository tests and security policy, and install-time scripts warrant extra operational review.
61%
Total Score
67
88
50
The package runs post-install and post-update Composer scripts, adding installation-time behavior that should be understood before use. No provided signal shows those scripts are harmful, so this is a caution rather than a severe risk.
The package has 21 releases since March 2016 but none in the last three years, with the latest published in September 2023. This is a meaningful maintenance concern despite its established history.
The repository recorded zero commits and zero active maintainers in the last three months. Although the last push was in March 2025, the recent inactivity raises abandonment risk.
There are 23 open issues and 9 open pull requests, but no issues or pull requests were opened or merged in the measured month. This supports caution about current responsiveness.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
topthink/framework Version ^6.0 || ^8.0 | — | — |
topthink/think-helper Version ^3.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.