Usable with caveats: this is a very new template with only one day of history, no demonstrated commit activity, and no security policy. It has a clear README, MIT licensing, a linked non-archived repository, and a small dependency surface, but its maintenance track record is not yet established.
58%
Total Score
50
100
71
50
The package uses a post-root-package-install script, which is an install-time behavior that deserves review before adoption even though it is common in Composer projects.
The package is only 1 day old with four releases and a median interval of about 4.6 hours, so there is not yet enough history to demonstrate sustained maintenance or release discipline.
The repository reports zero commits and zero active maintainers during the last 3 months. Because the package is only 1 day old this may reflect limited observation time, but it provides no evidence of an established maintenance process.
The repository name matches the package name, which is reassuring, but the README does not mention the package explicitly. This creates a modest concern that the registry package and repository linkage has not been clearly documented.
Composer is used as the build tool, but no security scanning tooling is present. For a new application template, this is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
watsonhaw/lychee-php Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.