The package is very new and has no recorded commits or active maintainers over the past three months. It includes substantial tests, a clear license, readme, and tightly scoped dependencies, but lacks a security policy and scanning.
62%
Total Score
67
100
81
83
The repository is owned by a personal GitHub account rather than an organization, so the project has no demonstrated organizational backing to compensate for its thin maintenance history.
The package is 0 days old with 10 releases, all within the first day; this shows active initial publishing but provides no evidence of sustained maintenance.
The repository records 0 commits and 0 active maintainers over the past three months. Because the project is brand new, this may reflect limited history, but it still leaves sustained maintenance unproven.
The repository uses Composer, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. This leaves vulnerability reporting and response expectations undocumented for a framework handling sessions, CSRF, authentication, and database access.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.