The package has clear documentation, tests, a license, and a matching source repository. It lacks a security policy and automated security scanning, so future issues may be slower to detect.
60%
Total Score
50
81
50
The package is about 15 months old, but its latest registry release was over 15 months ago and it had no releases in the last 12 months. The five releases were clustered within about a day, leaving no evidence of ongoing release maintenance.
The package declares a post-install command, so installation performs additional package-defined work beyond extracting files. That deserves review because install-time scripts increase dependency installation risk.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful abandonment concern, although the repository is not archived and the release includes supporting documentation and tests.
There were two open issues and no issue or pull-request activity in the last month. This adds limited evidence of low ongoing project activity but is weaker than the lack of recent commits.
Composer build tooling is present, but no security-scanning tool was detected. The missing security automation modestly reduces assurance for a package that handles application runtime infrastructure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.3 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
nyholm/psr7-server Version ^1.0 | — | — |
topthink/framework Version ^8.0 | — | — |
topthink/think-orm Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.