Usable with caveats: it has clear licensing, documentation, tests, and an active-looking repository, but the project is only one day old with eight releases and no recorded commits in the last three months. Its very early maturity and lack of security scanning make it a dependency to adopt cautiously.
62%
Total Score
50
50
78
83
The framework declares 13 runtime dependencies across storage, ORM, validation, templating, queues, and other subsystems. This breadth increases dependency and upgrade surface, though it is consistent with the package's framework scope.
The package is backed by a user-owned repository rather than an organization, so there is no broader organizational maintenance capacity evident from this signal.
The project is only 1 day old and has already published 8 releases, indicating an immature release process that has not yet demonstrated sustained maintenance.
No commits or active maintainers were recorded in the last three months, which is a serious maintenance concern; however, the project is only 1 day old and the repository was pushed recently, partly explaining the limited history.
The repository has 0 stars, forks, and watchers, so there is no community adoption evidence yet. This is consistent with the package's one-day age and is supporting rather than decisive evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.0 | — | — |
ramsey/uuid Version ^4.0 | — | — |
league/flysystem Version ^3.0 | — | — |
watsonhaw/think-orm Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.