The project is young and has stopped showing activity after its initial burst, while the assessed v0.7.0 conflicts with the registry's reported latest v0.1.0. Tests, a usable README, MIT licensing, organization backing, and a matching repository help, but security policy and scanning are absent.
48%
Total Score
50
100
75
75
There were zero commits and zero active maintainers in the last three months, leaving no observed evidence of ongoing fixes or maintenance after the initial release period.
The assessed release is v0.7.0, but the registry reports v0.1.0 as latest; this inconsistency materially weakens release traceability despite the package not being marked prerelease.
The package is only 168 days old with three releases, all released within a median of about 8 hours, indicating an initial burst without enough history to establish durable maintenance.
The repository uses Composer, but no security scanning tools were detected. Build tooling is present, while the missing scanning reduces supply-chain transparency for a server-side application.
No repository security policy was found, leaving disclosure and response practices undocumented for an application that handles accounts, authentication, messaging, and moderation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.8 | — | — |
vortexphp/framework Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.