The repository has no security policy or automated security scanning, and the project has no established release history. The MIT license, focused dependency set, and clear setup README help.
68%
Total Score
75
100
83
83
The repository is owned by an individual account rather than an organization, so there is no observed organizational backing to offset the project's very early maturity.
The package is only 0 days old, with 11 releases in roughly 14 hours and a median interval of about 1 hour 12 minutes. That burst shows active initial iteration but provides little evidence of sustained maintenance.
Composer is used for the build, which fits the ecosystem, but no security scanning tools are configured, leaving a modest assurance gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities in this framework starter.
Version v0.2.10 is not a prerelease, but the 0.x major version indicates an early API and project maturity stage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
whitesmoke/core Version ^0.2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.