The MIT license, focused dependency set, matching repository, and clear README support adoption. The small organization-backed project has no security policy or scanning, limiting evidence of ongoing oversight.
58%
Total Score
75
88
83
The package has had no releases in the last 12 months, and its latest release was nearly two years ago despite being only about two years old. This is meaningful abandonment risk, although the five releases were initially regular.
There were no new or closed issues or pull requests in the last month, while one issue and two pull requests remain open. This supports the broader indication that maintenance has slowed.
Composer is used for the build, which fits the package, but no security-scanning tooling is present. The missing scanning is a modest oversight gap for a dependency distributed to consumers.
The repository has no security policy, leaving vulnerability-reporting and response practices undocumented. This is a transparency gap, but not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
robmorgan/phinx Version ^0.16.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.