The package is small and clearly identified, with an MIT license, a usable README, and a GitHub release for this version. Its release and repository activity stopped about six years ago, while three issues remain open and no security policy or scanning is provided.
45%
Total Score
50
75
75
The package has only 4 releases and none in the last 12 months; its latest release was about six years ago. This is strong evidence of abandonment risk for a dependency.
There were 0 commits and 0 active maintainers in the last three months, consistent with a project that has been inactive for about six years. This materially increases abandonment risk.
No issues or pull requests were opened or closed in the last month, and 3 issues remain open. This supports the conclusion that maintenance is not currently active.
Composer build tooling is present, but no security scanning tools are reported. That is a modest transparency and hygiene gap, not a standalone reason to reject the package.
The linked repository is not archived, but its last push was about six years ago, so the non-archived status does not offset the evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.4 | — | — |
topthink/framework Version 6.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.