The stable release includes a README and release notes, but maintenance has stopped for about two years. The small user-owned project has little adoption, no recent commits, and no security policy, so future fixes are uncertain.
52%
Total Score
33
100
83
50
The repository had 0 commits and 0 active maintainers in the last three months, while the last push was about two years ago. This is the strongest evidence that maintenance has stalled.
The package runs a post-autoload-dump lifecycle script, adding install-time behavior that consumers should understand. This is a modest supply-chain and reproducibility concern, not a severe risk by itself.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the single-maintainer and inactive-project concerns.
The package has 8 releases but none in the last 12 months, and its latest release was about two years ago. This indicates a meaningful maintenance and abandonment risk despite the earlier release history.
There is one open issue and no issue or pull-request activity in the last month. This provides little evidence of active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
maximebf/debugbar Version ^1.19 | — | — |
topthink/framework Version ^6.0 | ^6.1 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.