The project has substantial recent development, repository tests, changelog support, build tooling, and security scanning. Its prerelease-heavy history, single registry publisher, absent security policy, and broad runtime dependency set warrant extra maintenance scrutiny.
70%
Total Score
70
50
93
50
The package declares 13 runtime dependencies spanning payments, email, authentication, image processing, and document generation. This broad dependency surface increases maintenance and transitive-risk burden compared with a narrowly scoped library.
Only one account has registry publish access, which is a narrow publishing path. Repository activity shows two active contributors, partly compensating for the registry-side concentration but not eliminating the release-account dependency.
The repository is owned by a user account rather than an organization, so there is no provided organizational backing to offset the narrow maintainer base. The two active contributors provide some practical compensation.
The repository has four open issues but no issues or pull requests were opened or closed in the last month. This is a small transparency concern, though it is outweighed by the strong recent commit activity.
No repository security policy was found. For a framework with authentication, payments, email, and other integrations, the absence of a documented vulnerability-reporting process is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fpdf/fpdf Version ^1.86 | — | — |
klaviyo/api Version ^18.0 | — | — |
firebase/php-jwt Version ^6.11 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
composer/composer Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.