Usable with caveats: it is well documented, tested, licensed, and linked to a matching repository, but maintenance appears to have stalled for about nine months and the project has no security policy or scanning. Its small, unproven repository and large dependency surface warrant review before adopting it broadly.
68%
Total Score
25
50
69
80
There were no commits and no active maintainers in the last three months, which is the strongest evidence of currently stalled maintenance despite the repository not being archived.
The package declares 30 runtime dependencies, including framework, database, administration, and related WeChat Work bundles; that broad dependency surface increases integration and update burden.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so the package has limited visible institutional backing.
Only two releases have been published across about 15 months, with one release in the last year and a median interval of about 160 days; this indicates a young, slow-moving project rather than an established release cadence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the limited release and commit history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
nesbot/carbon Version ^2.72 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.